Re: [PATCH] lib: memcmp_nta: add timing-attack secure memcmp

From: Florian Weimer
Date: Mon Feb 11 2013 - 14:18:09 EST


* Daniel Borkmann:

> + * memcmp_nta - memcmp that is secure against timing attacks

It's not providing an ordering, so it should not have "cmp" in the
name.

> + for (su1 = cs, su2 = ct; 0 < count; ++su1, ++su2, count--)
> + res |= (*su1 ^ *su2);

The compiler could still short-circuit this loop. Unlikely at
present, but this looks like a maintenance hazard.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/