5 ms·
I am wondering how that relates to searching for the token in a database (index). Does it still matter? I would assume the time might depend on where or even we
by csnweb 5y ago
I am wondering how that relates to searching for the token in a database (index). Does it still matter? I would assume the time might depend on where or even wether the token is in the index or not, not sure how much though and what to do about it.
- ezekg 5y agoRun the token through a secure HMAC function before storing it in the DB. Problem solved. KISS. :)
- iudqnolq 5y agoWhy would something derived from a random string have better comparison properties than the random string?
- ezekg 5y agoYou can’t perform a timing attack for a token “foo” in SELECT WHERE token = :token if the token stored in the DB is the HMAC of “foo”. E.g. trying “f” and then “fo” produce 2 entirely different, random tokens from the query’s POV. The attacker could never deduce that the correct token is “foo.”
- simonw 5y agoYes, it matters - timing attacks could absolutely work against an indexed column in a database. The trick I've used for this is to have tokens that look like this: "234523:7a561002f780e23853bdfbd89ae79bf2" Then you have database entries like this: id = 234523 token = 7a561002f780e23853bdfbd89ae79bf2 When a token comes in you use the bit before the : to look up the database record by its indexed ID, then perform a safe comparison between the rest of the token and the value you retrieved from the database.
- bpicolo 5y agoSerious question - what makes the database serialization not vulnerable to timing attacks in the same vein? I wouldn't expect those to be purely constant time implementations.
- simonw 5y agoYou do the final comparison outside of the database after retrieving the stored value - I use the Python secrets.compare_digest() function for that.
- zaroth 5y agoI’d rather store an HMAC of the token. That way you’re hashing the user input, which sanitizes it. It also protects against timing attacks.* And most importantly it protects against credentials leaking. Even insiders who can read a token from the database can’t use it to authenticate, because the app logic expects a pre-image of that value. *HMAC resists timing attacks because the attacker can no longer control the bit pattern on either side of the equality check.
- some_furry 5y ago> I am wondering how that relates to searching for the token in a database (index). Does it still matter? It can, but the practicality of exploiting this timing leak isn't at all a settled issue. Previously, https://soatok.blog/2021/08/20/lobste-rs-password-reset-vulnerability/ https://soatok.blog/2021/08/20/lobste-rs-password-reset-vuln...
- deleted 5y ago[deleted]