Use constant-time HMAC comparison in Nigori.
Cryptography is timing-sensitive. MACs should never be compared with usual string comparison functions, only constant-time checks. Use HMAC::Verify. Bug: none Change-Id: Ic1b164441396e4a4a853f1a50d91bc8f5c7fa18e Reviewed-on: https://chromium-review.googlesource.com/1246323Reviewed-by:vitaliii <vitaliii@chromium.org> Commit-Queue: David Benjamin <davidben@chromium.org> Cr-Commit-Position: refs/heads/master@{#594737}
Showing
Please register or sign in to comment