Skip to content

fix: use constant-time comparison for callback signatures - #48

Open
eradeshahi wants to merge 1 commit into
ixopay:mainfrom
eradeshahi:fix/constant-time-callback-signature
Open

fix: use constant-time comparison for callback signatures#48
eradeshahi wants to merge 1 commit into
ixopay:mainfrom
eradeshahi:fix/constant-time-callback-signature

Conversation

@eradeshahi

Copy link
Copy Markdown

The callback signature is currently compared using "==" or "===",These comparisons are not designed for sensitive cryptographic values and may return as soon as they find a different byte

Because of this, the response time can be slightly different depending on how much of the provided signature matches the expected signature. By sending many requests and measuring these timing differences, an attacker may be able to guess the signature step by step.

Using "hash_equals()" prevents this issue because it compares the signatures in constant time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants