diff options
| author | nanalelfe <nargiza.nosirova@mail.utoronto.ca> | 2016-07-27 12:46:04 +0000 |
|---|---|---|
| committer | nanalelfe <nargiza.nosirova@mail.utoronto.ca> | 2016-07-27 12:46:04 +0000 |
| commit | 7bee9b7e0968b650b3dbe2e35bf3a0d7d6e5e00e (patch) | |
| tree | 4e63af46a6e306bfeac1ef4b8bd83e1b45a37257 /node_modules/tsscmp/README.md | |
| parent | 6520aa92a114d65b17b178a952c8985e84afd231 (diff) | |
Removed some unused modules with prune
Diffstat (limited to 'node_modules/tsscmp/README.md')
| -rw-r--r-- | node_modules/tsscmp/README.md | 48 |
1 files changed, 0 insertions, 48 deletions
diff --git a/node_modules/tsscmp/README.md b/node_modules/tsscmp/README.md deleted file mode 100644 index cba99d0..0000000 --- a/node_modules/tsscmp/README.md +++ /dev/null @@ -1,48 +0,0 @@ -# Timing safe string compare using double HMAC - -[](https://nodejs.org/en/download) -[](https://npmjs.org/package/tsscmp) -[](https://npmjs.org/package/tsscmp) -[](https://travis-ci.org/suryagh/tsscmp) -[](https://ci.appveyor.com/project/suryagh/tsscmp) -[](https://david-dm.org/suryagh/tsscmp) -[](LICENSE) - - -Prevents [timing attacks](http://codahale.com/a-lesson-in-timing-attacks/) using Brad Hill's -[Double HMAC pattern](https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verification/) -to perform secure string comparison. Double HMAC avoids the timing atacks by blinding the -timing channel using random time per attempt comparison against iterative brute force attacks. - - -## Install - -``` -npm install tsscmp -``` -## Why -To compare secret values like **authentication tokens**, **passwords** or -**capability urls** so that timing information is not -leaked to the attacker. - -## Example - -```js -var timingSafeCompare = require('tsscmp'); - -var sessionToken = '127e6fbfe24a750e72930c'; -var givenToken = '127e6fbfe24a750e72930c'; - -if (timingSafeCompare(sessionToken, givenToken)) { - console.log('good token'); -} else { - console.log('bad token'); -} -``` -##License: -[MIT](LICENSE) - -**Credits to:** [@jsha](https://github.com/jsha) | -[@bnoordhuis](https://github.com/bnoordhuis) | -[@suryagh](https://github.com/suryagh) | -
\ No newline at end of file |
