3 ms·
Precisely what Thomas said. Using == instead of hmac.compare_digest is unlikely to be a source of vulnerabilities in your application, but it's a good habit to
by sarciszewski 11y ago
Precisely what Thomas said.
Using == instead of hmac.compare_digest is unlikely to be a source of vulnerabilities in your application, but it's a good habit to get into whenever you touch cryptography.
See also: https://news.ycombinator.com/item?id=10345965 https://news.ycombinator.com/item?id=10345965 (pg. 33-36, 42-43 of the PDF)
Again consider timing leaks.
Many interesting questions:
How do secrets affect timings?
How can attacker see timings?
How can attacker choose inputs to influence how secrets affect timings?
Et cetera.
The boring-crypto alternative: crypto software is built from instructions
that have no data flow from inputs to timings.
Obviously constant time.