3 ms·
As mentioned elsewhere in the thread, this isn't a "you must", this is a "you might as well". Timing attacks depend on an attacker having control over the hash
by Freaky 11y ago
As mentioned elsewhere in the thread, this isn't a "you must", this is a "you might as well".
Timing attacks depend on an attacker having control over the hash being compared (e.g. they have a HMAC in a cookie they're sending you, and they can adjust it character by character) - with randomised secret salts and server-side hashing, this isn't the case.
The SCrypt example is the one I'm more concerned with. The defaults there are 1MB of RAM and 64-bit salts, both of which could do with increasing. I have an open issue on this: https://github.com/pbhogan/scrypt/issues/25 https://github.com/pbhogan/scrypt/issues/25
As it is, the example would probably be better as this:
password = SCrypt::Password.create(usersPassword, salt_size: 32, max_mem: 16*1024*1024)
You'll be pleased to know SCrypt::Password#== is at least constant-time.