[TASK] Compare password hashes in constant time
In order to avoid time-based hash-based attacks, the native PHP security functions are used instead of simple string comparisons, when comparing passwords with hashes. Change-Id: I0dbe2c12c5017f9d71ea7628ddd35d919510ac12 Releases: master Resolves: #79888 Related: #79795 Reviewed-on: https://review.typo3.org/51737 Reviewed-by:Helmut Hummel <typo3@helhum.io> Tested-by:
Helmut Hummel <typo3@helhum.io> Tested-by:
TYPO3com <no-reply@typo3.com> Reviewed-by:
Mads Lønne Jensen <mlj@systime.dk> Reviewed-by:
Markus Klein <markus.klein@typo3.org> Tested-by:
Markus Klein <markus.klein@typo3.org>
Showing
- typo3/sysext/saltedpasswords/Classes/Salt/Md5Salt.php 1 addition, 1 deletiontypo3/sysext/saltedpasswords/Classes/Salt/Md5Salt.php
- typo3/sysext/saltedpasswords/Classes/Salt/Pbkdf2Salt.php 1 addition, 1 deletiontypo3/sysext/saltedpasswords/Classes/Salt/Pbkdf2Salt.php
- typo3/sysext/saltedpasswords/Classes/Salt/PhpassSalt.php 1 addition, 1 deletiontypo3/sysext/saltedpasswords/Classes/Salt/PhpassSalt.php
- typo3/sysext/saltedpasswords/Tests/Unit/Salt/BlowfishSaltTest.php 27 additions, 0 deletions...sext/saltedpasswords/Tests/Unit/Salt/BlowfishSaltTest.php
- typo3/sysext/saltedpasswords/Tests/Unit/Salt/Md5SaltTest.php 27 additions, 0 deletionstypo3/sysext/saltedpasswords/Tests/Unit/Salt/Md5SaltTest.php
- typo3/sysext/saltedpasswords/Tests/Unit/Salt/Pbkdf2SaltTest.php 27 additions, 0 deletions...sysext/saltedpasswords/Tests/Unit/Salt/Pbkdf2SaltTest.php
- typo3/sysext/saltedpasswords/Tests/Unit/Salt/PhpassSaltTest.php 27 additions, 0 deletions...sysext/saltedpasswords/Tests/Unit/Salt/PhpassSaltTest.php
Please register or sign in to comment