Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-13203

Use constant time comparison method for comparing password hashes

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • 3.1.0-RC5
    • 3.1.0-RC6
    • Login
    • None

    Description

      Password hashes should be compared byte by byte to have a constant execution time for all hashes with the same length.

      Attachments

        Activity

          People

            Marc Marc
            Marc Marc
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: