Skip to content

Crypto library should have a constant-time equality function #3043

Description

@bbqsrc

Issue #8560 was archived, but seems no issue was opened for it here.

I note that there is still no constant-time equality method in the converged node.

Activity

  1. added
    cryptoIssues and PRs related to the crypto subsystem.
    feature requestIssues requesting new Node.js features.
    on Sep 24, 2015
  2. ChALkeR commented on Sep 26, 2015

    @ChALkeR
    Member

    This doesn't look like a feature request. If a timing attack could be reproduced in any setup based on this, then it's a security issue. If it can't, then it's speculative.

    Ah, sorry all. It's indeed a feature request, because there is no such function at all in the crypto module. And definetely not a security issue.

    I misread, sorry again.

  3. added
    feature requestIssues requesting new Node.js features.
    and removed
    feature requestIssues requesting new Node.js features.
    on Sep 26, 2015
  4. norcalli commented on Jan 16, 2016

    @norcalli

    The only time a constant-time equality comparison is a useful thing to do is as a countermeasure to a timing attack, therefore I think it is definitely a security issue and I'm a bit surprised it isn't in the crypto module.

  5. ChALkeR commented on Feb 8, 2016

    @ChALkeR
    Member

    #5139 and #3073 are the PRs for this.

  6. ChALkeR commented on Sep 12, 2016

    @ChALkeR
    Member

    #8040 landed (see also #8304).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.feature requestIssues requesting new Node.js features.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions