[issue15061] hmac.secure_compare() leaks information about length of strings

Maciej Fijalkowski report at bugs.python.org
Thu Jun 21 16:03:10 CEST 2012


Maciej Fijalkowski <fijall at gmail.com> added the comment:

Hi.

This is what we did with Armin: http://bpaste.net/show/32123/

It seems there is still *some* information leaking via side-channels, although it's a bit unclear what. Feel free to play with it (try swapping, having different object etc.)

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue15061>
_______________________________________


More information about the Python-bugs-list mailing list