Re: [VOTE] Timing attack safe string comparison function

From: Date: Thu, 06 Feb 2014 04:23:23 +0000
Subject: Re: [VOTE] Timing attack safe string comparison function
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message

On 2/5/14 7:56 PM, Yasuo Ohgaki wrote:
Hi all, Padraic gave me an another idea of additional mitigation for this.
What's the status of the RFC? It's listed as under voting but there is deep discussion still ongoing. The RFC is very short on technical detail. It is also lacking an end-of-vote date. It's not clear what the RFCs path forward is. (If this info is in a mail thread, but not in the RFC then remember readers/voters should not have to trawl internals mail to understand the proposal and its direction). Personally, I suggest the vote be closed/withdrawn with the assumption the concept was accepted 15 to 1. Then work on the code until a mutually acceptable and useful implementation is found. After that, a quick vote can be made on the implementation. Chris -- [email protected] http://twitter.com/ghrd Free PHP & Oracle book: http://www.oracle.com/technetwork/topics/php/underground-php-oracle-manual-098250.html

Thread (54 messages)

« previous php.internals (#72315) next »