Re: [VOTE] Timing attack safe string comparison function

From: Date: Tue, 18 Mar 2014 11:23:25 +0000
Subject: Re: [VOTE] Timing attack safe string comparison function
References: 1 2  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message

On 18.03.2014, at 02:04, Yasuo Ohgaki <[email protected]> wrote:

> On Mon, Feb 3, 2014 at 7:50 AM, Rouven Weßling <[email protected]> wrote:
> 
>> Hi internals,
>> 
>> as I've received no further feedback I've opened the voting on "Timing
>> attack safe string comparison function":
>> 
>> - https://wiki.php.net/rfc/timing_attack
>> 
> 
> Is there any progress?

The pull request (https://github.com/php/php-src/pull/608) for that RFC is waiting to be merged, I
hope someone gets to it before beta1.

> From benchmark result, overhead for timing safe comparison is negligible
> with byte by byte comparison.
> I would like to see timing safe "===" for 5.6, if it's possible. (== could
> be timing safe, too)
> 
> Is anyone working on it?

I don't know if someone else is, but I am not.

Best regards
Rouven


Thread (54 messages)

« previous php.internals (#73268) next »