Re: [VOTE] Timing attack safe string comparison function

From: Date: Tue, 04 Feb 2014 04:30:06 +0000
Subject: Re: [VOTE] Timing attack safe string comparison function
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi all,

On Tue, Feb 4, 2014 at 1:06 PM, Yasuo Ohgaki <[email protected]> wrote:

> It's enough for hash functions up to 1024 bits. For SHA-3, we may set
> larger minimum.


Just an additional note.
AFAIK, SHA-3 also has 512 bits maximum.
Since it has more bits internally, it may be extended.
There may be hash functions that have larger bits.
256 iterations would be long enough for many years.

Regards,

--
Yasuo Ohgaki
[email protected]


Thread (54 messages)

« previous php.internals (#72168) next »