Skip to content

Fix potential time attack vulnerability in HMAC signature comparison

Compare
Choose a tag to compare
@rbone rbone released this 18 Jan 22:02
· 29 commits to master since this release

Fixes a potential timing attack vulnerability in our HMAC signature comparison using a double HMAC approach. Thanks to @afk11 for submitting this.