#memcmp

2025-10-30

Lỗ hổng thời gian trong hàm memcmp có thể gây ra rò rỉ thông tin bí mật. Sử dụng thư viện Flatline để viết code an toàn và không bị rò rỉ thời gian. #an_toàn_thời_gian #lỗ_hổng_thời_gian #memcmp #Flatline #constant_time #security

reddit.com/r/programming/comme

2023-05-28

I fell into a rabbit hole today on memcmp() timing analysis for a remote service that verifies a MD5 digest... hours later, it's clear that due to compiler optimizations this is _really_ hard to exploit on most 64-bit machines (it can turn into 2^64 brute force in many cases).

Any tips on modern (remote) timing analysis of memcmp() implementations?

Also, Erlang should probably stop using memcmp() for cookie digest verification.

#erlang #infosec #memcmp

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst