-
Notifications
You must be signed in to change notification settings - Fork 30.7k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Crypto library should have a constant-time equality function #3043
Comments
Ah, sorry all. It's indeed a feature request, because there is no such function at all in the I misread, sorry again. |
The only time a constant-time equality comparison is a useful thing to do is as a countermeasure to a timing attack, therefore I think it is definitely a security issue and I'm a bit surprised it isn't in the crypto module. |
Issue #8560 was archived, but seems no issue was opened for it here.
I note that there is still no constant-time equality method in the converged node.
The text was updated successfully, but these errors were encountered: