Message162587
| Author |
ncoghlan |
| Recipients |
Jon.Oberheide, ncoghlan, neologix, pitrou, python-dev, r.david.murray, sbt, vstinner |
| Date |
2012年06月10日.15:16:24 |
| SpamBayes Score |
-1.0 |
| Marked as misclassified |
Yes |
| Message-id |
<1339341385.6.0.0171386457531.issue14532@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
A comment above the length check referring back to this issue and the deliberate decision to allow a timing attack to determine the length of the expected digest would be handy.
I was just looking at hmac.secure_compare and my thought when reading the source and the docstring was "No, it's not time-independent, you can still use a timing attack to figure out the expected digest length". |
|