-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 On 21/03/14 12:52, Michael Rogers wrote: > Thanks for the pointer. The Javadoc doesn't say whether this is a > constant-time comparison. In OpenJDK 6 it isn't. In OpenJDK 7 it > does something similar to my original suggestion. So unfortunately > it seems like this might be a case where bicycle-invention is > necessary. >
Sorry for the self-reply: wrong link. I resign from this thread. ;-) http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-b14/java/security/MessageDigest.java#MessageDigest.isEqual%28byte%5B%5D%2Cbyte%5B%5D%29 Cheers, Michael -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBCAAGBQJTLDdJAAoJEBEET9GfxSfMOCoH/j0g68J7m8zDAvFb6tZB7lUJ QaCoU5mYf2uh64dW7j7e9rNZdV8P938gS5348V6Tb/UyQC8QXlF0dWbWALb3iQG8 ZU74LB+bMyhe2vtJKt86PnkwJR7MfrnZq2xIZowaxKWXtHqQS2BzsU2Q8sinu9By 78p9EYdiuxDOGK7BwtR4yqq93voBHKo0i/j8oOSWnj1OOmYOTgoPXVL08s7Iznvl IIdt3ZoqM0UIuB/a8ZvhY+KCp1K/zXZIX9KmR2MOxKtFSLgz7LRBlv58i6lBAaXD wA/4L2e4exNi0zUMfDihpjPpaj1Sp/yTbqlXH9SekrwHO1QNchEpS+H+qBtaXJk= =55xn -----END PGP SIGNATURE----- -- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, change to digest, or change password by emailing moderator at [email protected].
