3 ms·
Tracking units of measurement is so important for security (bits vs bytes vs BN_ULONGs). There was a bug a few years ago with Bouncy Castle using 16 bit vs 16 b
by nmadden 4y ago
Tracking units of measurement is so important for security (bits vs bytes vs BN_ULONGs). There was a bug a few years ago with Bouncy Castle using 16 bit vs 16 byte keys, IIRC, due to a similar mixup. Ideally units are captured in the type system, but I've found that even naming methods/fields appropriately (e.g. setTimeoutInSeconds(long) vs setTimeout(long)) goes a long way to reducing these kinds of bugs.
- testplzignore 4y agoIt's 2022 and we still have new code being written with single letter variable names. Totally crazy. The variable names used in the functions added: a b m r carry mask num tmp Madness.
- hannob 4y agoIn crypto code you often have conventions to name a certain value with a letter. E.g. RSA public keys consist of the values N, e, private keys also have d, p, q etc. One may argue whether a, b and m are as "commonly known" for modular exponentiation. Still: There are definitely valid cases to use single letter variable names if they are the most well known "names" of certain values.
- mistrial9 4y agothis comes from a culture of obscurity and cryptic writings.. thirty character variable names? no way ; single character variable names? terse no context variable names ? variables used in differerent local blocks with the same names? really, clueless ..
- segfaultbuserr 4y agoMath and crypto code are different from business logic. Under some circumstances, it's acceptable to use single-letter variable names. This often happens when the code implements a mathematical operation according to a standard formula. For example, the following SHA-256 code comes from OpenBSD - a Unix derivative known for its focus on security and correctness. do { /* Rounds 0 to 15 (unrolled): */ ROUND256_0_TO_15(a,b,c,d,e,f,g,h); ROUND256_0_TO_15(h,a,b,c,d,e,f,g); ROUND256_0_TO_15(g,h,a,b,c,d,e,f); ROUND256_0_TO_15(f,g,h,a,b,c,d,e); ROUND256_0_TO_15(e,f,g,h,a,b,c,d); ROUND256_0_TO_15(d,e,f,g,h,a,b,c); ROUND256_0_TO_15(c,d,e,f,g,h,a,b); ROUND256_0_TO_15(b,c,d,e,f,g,h,a); } while (j < 16); In this particular case, the code is a direct translation of math, following the paper's notations is preferable. The state variables are named a, b, c, d, e, f, g because they're what the authors of SHA-256 chose to call them. When writing this particular fragment of code, renaming the state variables to something else is not constructive and increases the chance of mistakes. I haven't read the OpenSSL code in question so I cannot comment whether the uses of single-letter variables in your comment are appropriate. To make an educated guess, a, b, m, r are probably reasonable. The uses of carry, mask, num, tmp are potentially questionable, though.
- christophilus 4y agoI use single letter variable names all the time. emails = users.map u -> u.email It’s perfectly reasonable when the context is brief and the usage is obvious.