Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-13203

Use constant time comparison method for comparing password hashes

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 3.1.0-RC6
    • 3.1.0-RC5
    • Login
    • None

      Password hashes should be compared byte by byte to have a constant execution time for all hashes with the same length.

            Marc Marc
            Marc Marc
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: