aboutsummaryrefslogtreecommitdiff
path: root/node_modules/tsscmp/README.md
diff options
context:
space:
mode:
authornanalelfe <nargiza.nosirova@mail.utoronto.ca>2016-07-21 06:40:43 +0000
committernanalelfe <nargiza.nosirova@mail.utoronto.ca>2016-07-21 06:40:43 +0000
commit39ef1b6fd37bb9b725676d3a98f13e3450798200 (patch)
treeeeec60d5b56e5c69a3ba251d98a27f4684d47066 /node_modules/tsscmp/README.md
parentee8e1a13b60a6adfdc691b2a9b57289188397641 (diff)
parent76757d227f64e35a093d47facc260d9266e2bf38 (diff)
MERGED
Diffstat (limited to 'node_modules/tsscmp/README.md')
-rw-r--r--node_modules/tsscmp/README.md48
1 files changed, 48 insertions, 0 deletions
diff --git a/node_modules/tsscmp/README.md b/node_modules/tsscmp/README.md
new file mode 100644
index 0000000..cba99d0
--- /dev/null
+++ b/node_modules/tsscmp/README.md
@@ -0,0 +1,48 @@
+# Timing safe string compare using double HMAC
+
+[![Node.js Version](https://img.shields.io/node/v/tsscmp.svg?style=flat-square)](https://nodejs.org/en/download)
+[![npm](https://img.shields.io/npm/v/tsscmp.svg?style=flat-square)](https://npmjs.org/package/tsscmp)
+[![NPM Downloads](https://img.shields.io/npm/dm/tsscmp.svg?style=flat-square)](https://npmjs.org/package/tsscmp)
+[![Build Status](https://img.shields.io/travis/suryagh/tsscmp/master.svg?style=flat-square)](https://travis-ci.org/suryagh/tsscmp)
+[![Build Status](https://img.shields.io/appveyor/ci/suryagh/tsscmp/master.svg?style=flat-square&label=windows)](https://ci.appveyor.com/project/suryagh/tsscmp)
+[![Dependency Status](http://img.shields.io/david/suryagh/tsscmp.svg?style=flat-square)](https://david-dm.org/suryagh/tsscmp)
+[![npm-license](http://img.shields.io/npm/l/tsscmp.svg?style=flat-square)](LICENSE)
+
+
+Prevents [timing attacks](http://codahale.com/a-lesson-in-timing-attacks/) using Brad Hill's
+[Double HMAC pattern](https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verification/)
+to perform secure string comparison. Double HMAC avoids the timing atacks by blinding the
+timing channel using random time per attempt comparison against iterative brute force attacks.
+
+
+## Install
+
+```
+npm install tsscmp
+```
+## Why
+To compare secret values like **authentication tokens**, **passwords** or
+**capability urls** so that timing information is not
+leaked to the attacker.
+
+## Example
+
+```js
+var timingSafeCompare = require('tsscmp');
+
+var sessionToken = '127e6fbfe24a750e72930c';
+var givenToken = '127e6fbfe24a750e72930c';
+
+if (timingSafeCompare(sessionToken, givenToken)) {
+ console.log('good token');
+} else {
+ console.log('bad token');
+}
+```
+##License:
+[MIT](LICENSE)
+
+**Credits to:** [@jsha](https://github.com/jsha) |
+[@bnoordhuis](https://github.com/bnoordhuis) |
+[@suryagh](https://github.com/suryagh) |
+ \ No newline at end of file