SEC-1666: Use constant time comparison for sensitive data.

Constant time comparison helps to mitigate timing attacks. See the following link for more information

 * http://rdist.root.org/2010/07/19/exploiting-remote-timing-attacks/
 * http://en.wikipedia.org/wiki/Timing_attack for more information.
This commit is contained in:
Rob Winch
2011-01-31 23:00:16 -06:00
parent 6a62b51870
commit 8c08eeb57b
9 changed files with 145 additions and 13 deletions

View File

@@ -16,6 +16,12 @@ public class StandardPasswordEncoderTests {
assertTrue(encoder.matches("password", result));
}
@Test
public void matchesLengthChecked() {
String result = encoder.encode("password");
assertFalse(encoder.matches("password", result.substring(0,result.length()-1)));
}
@Test
public void notMatches() {
String result = encoder.encode("password");