8000 Statistical report for constant time compare tests? · Issue #266 · kelektiv/node.bcrypt.js · GitHub
[go: up one dir, main page]

Skip to content
Statistical report for constant time compare tests? #266
@ericelliott

Description

@ericelliott

Hi,

I'm the maintainer of Credential. We're currently trying to harden our constant time equality check in Credential, and we're looking for a good statistics test to ensure that our timing is constant enough to thwart timing attacks.

Your experience and feedback would be very useful. Please take a look at this proposed constant time string comparison. I'm especially interested in producing a test suite that can guarantee statistically significant constant time equality comparisons, and I believe such tests would be useful to node.bcrypt, as well.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0