buildkite-signed-pipeline icon indicating copy to clipboard operation
buildkite-signed-pipeline copied to clipboard

Use a constant time comparison for checking the signatures

Open zsims opened this issue 5 years ago • 0 comments

This is to mitigate against timing attacks, e.g. https://verboselogging.com/2012/08/20/a-timing-attack-in-action

zsims avatar Oct 01 '18 04:10 zsims