-
-
Notifications
You must be signed in to change notification settings - Fork 109
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is this a timing attack? #70
Comments
Summary Still relevant? Next steps
|
IMHO technically that would be a vulnerability. Even if the lines don't make too much sense and include more dangerous vulnerabilities as hardcoding the value to check against, the use of |
@jesusprubio I disagree, as I'm struggling to imagine how this could result in a compromise taking place or how this falls within the scope of this rule. Isn't this vulnerability about comparisons that take an amount of time related to how correct they are? That should only possibly apply to strings, numbers, etc., not |
This doesn't seem right.
The text was updated successfully, but these errors were encountered: