-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 21/03/14 12:52, Michael Rogers wrote:
> Thanks for the pointer. The Javadoc doesn't say whether this is a 
> constant-time comparison. In OpenJDK 6 it isn't. In OpenJDK 7 it
> does something similar to my original suggestion. So unfortunately
> it seems like this might be a case where bicycle-invention is
> necessary.
> 

Sorry for the self-reply: wrong link. I resign from this thread. ;-)

http://grepcode.com/file/repository.grepcode.com/java/root/jdk/openjdk/6-b14/java/security/MessageDigest.java#MessageDigest.isEqual%28byte%5B%5D%2Cbyte%5B%5D%29

Cheers,
Michael

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBCAAGBQJTLDdJAAoJEBEET9GfxSfMOCoH/j0g68J7m8zDAvFb6tZB7lUJ
QaCoU5mYf2uh64dW7j7e9rNZdV8P938gS5348V6Tb/UyQC8QXlF0dWbWALb3iQG8
ZU74LB+bMyhe2vtJKt86PnkwJR7MfrnZq2xIZowaxKWXtHqQS2BzsU2Q8sinu9By
78p9EYdiuxDOGK7BwtR4yqq93voBHKo0i/j8oOSWnj1OOmYOTgoPXVL08s7Iznvl
IIdt3ZoqM0UIuB/a8ZvhY+KCp1K/zXZIX9KmR2MOxKtFSLgz7LRBlv58i6lBAaXD
wA/4L2e4exNi0zUMfDihpjPpaj1Sp/yTbqlXH9SekrwHO1QNchEpS+H+qBtaXJk=
=55xn
-----END PGP SIGNATURE-----
-- 
Liberationtech is public & archives are searchable on Google. Violations of 
list guidelines will get you moderated: 
https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, 
change to digest, or change password by emailing moderator at 
compa...@stanford.edu.

Reply via email to