Re: [VOTE] Timing attack safe string comparison function

From: Date: Mon, 03 Feb 2014 12:23:53 +0000
Subject: Re: [VOTE] Timing attack safe string comparison function
References: 1  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message


On 02/02/14 22:50, Rouven Weßling wrote:
as I've received no further feedback I've opened the voting on "Timing attack safe string comparison function":
I've voted yes. However, at the risk of opening more bikeshedding again, I should say that I don't think hash_compare is an appropriate name. It's a timing attack-safe string comparison function, so I think something like str_equals_time_constant might be better as it is not so much a hash comparison function as a string comparison function. -- Andrea Faulds http://ajf.me/

Thread (54 messages)

« previous php.internals (#72084) next »