3 ms·
The best part there is that even the intended code is probably insecure, since == will likely open you to timing attacks and should be replaced with a secure co
by mnutt 6y ago
The best part there is that even the intended code is probably insecure, since == will likely open you to timing attacks and should be replaced with a secure comparison function.
- jpab 6y agoUnless it's also a non-cryptographic hash then I don't see how a timing attack does anything interesting here. Timing will potentially tell you how many bytes of the hash match. But finding a password that produces a hash that matches the first N bytes does not help you find a password that matches the N+1th byte, so you're still just left with a brute force attack. What am I missing? (Genuinely curious - I'm not a crypto expert)
- aliceryhl 6y agoAs long as the system isn't written such that only the hash is necessary to log in, it should be fine to just compare hashes normally.