Skip to content

Use a timing-safe equality check for passwords #133

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 9, 2019

Conversation

mcpower
Copy link
Contributor

@mcpower mcpower commented Mar 8, 2019

As the current implementation of password checking uses === to check equality, it is susceptible to timing attacks - see this article for more information.

This PR uses safe-compare to compare passwords without the possibility of a timing attack.

(Note that I could not test this change, as I was unable to successfully build the project. Please confirm that this change does not break anything before merging it!)

@kylecarbs kylecarbs merged commit c471bab into coder:master Mar 9, 2019
andreimc added a commit to devonlineco/code-server that referenced this pull request Mar 11, 2019
* upstream/master: (35 commits)
  Dockerfile: use relative path instead of $PWD for CMD
  Update docker oneliner and fix clone task
  Clone exact vscode release branch when build task (coder#167)
  Add -t flag to docker example (coder#181)
  Reverts parts of my last PR (coder#177)
  Fix build and Dockerfile issues (coder#176)
  Add nginx reverse proxy guide for selfhosted
  Use a timing-safe equality check for passwords (coder#133)
  Open websocket on same path as page (coder#149)
  Adhere to XDG base directory spec for dataDir and logDir (coder#156)
  Improve github issue template (coder#162)
  Fix typo: environemnt -> environment (coder#159)
  Add back web class
  Move upx compression behind an env flag
  ci: enable travis npm cache (coder#110)
  Improve .dockerignore (coder#111)
  Feature/1.32.0 update (coder#117)
  Update grammar on README (coder#139)
  inital -> initial (coder#135)
  Handle arch in dockerfile and add PR template (coder#109)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants