Skip to content

Conversation

nvx
Copy link

@nvx nvx commented Sep 28, 2021

Currently the user and pass hashes are compared separately, if the username matches but not the password the middleware will return slightly faster than if both the username and password are wrong.

This change concatenates the user and pass hashes together and compares them in one call to subtle.ConstantTimeCompare removing any timing leaks.

I also added a go.mod file.

nvx added 2 commits September 28, 2021 19:22
username is correct but not the password via a timing side channel.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant