Project

General

Profile

Actions

Task #83329

closed

Use hash_equals for timing-safe comparison of hash-values

Added by Stefan Neufeind almost 7 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Security
Target version:
-
Start date:
2017-12-14
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
9
PHP Version:
Tags:
Complexity:
Sprint Focus:

Description

To prevent timing-attacks on hash-comparions it is advised to use hash_equals (https://secure.php.net/hash_equals).

Actions

Also available in: Atom PDF