Re: [RFC] Timing-Safe Encoding Functions
| From: | Yasuo Ohgaki | Date: | Sun, 15 Mar 2015 02:17:00 +0000 |
| Subject: | Re: [RFC] Timing-Safe Encoding Functions | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-84797@lists.php.net to get a copy of this message | ||
Hi Scott,
On Sat, Mar 14, 2015 at 3:22 AM, Scott Arciszewski <scott@arciszewski.me>
wrote:
> https://wiki.php.net/rfc/timing_safe_encoding
Nice to see this RFC.
I haven't looked into patch yet, but no objections for the idea from me.
Only concern is existing timing safe function name. i.e. hash_equals()
http://php.net/manual/en/function.hash-equals.php
This function is better to named hash_equal_ts() if we are trying to have
consistent function names. (Old name should be alias, of course)
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net