blob: cba99d03700b1c5aadda61cee9cb04f9b0c27153 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
|
# Timing safe string compare using double HMAC
[](https://nodejs.org/en/download)
[](https://npmjs.org/package/tsscmp)
[](https://npmjs.org/package/tsscmp)
[](https://travis-ci.org/suryagh/tsscmp)
[](https://ci.appveyor.com/project/suryagh/tsscmp)
[](https://david-dm.org/suryagh/tsscmp)
[](LICENSE)
Prevents [timing attacks](http://codahale.com/a-lesson-in-timing-attacks/) using Brad Hill's
[Double HMAC pattern](https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verification/)
to perform secure string comparison. Double HMAC avoids the timing atacks by blinding the
timing channel using random time per attempt comparison against iterative brute force attacks.
## Install
```
npm install tsscmp
```
## Why
To compare secret values like **authentication tokens**, **passwords** or
**capability urls** so that timing information is not
leaked to the attacker.
## Example
```js
var timingSafeCompare = require('tsscmp');
var sessionToken = '127e6fbfe24a750e72930c';
var givenToken = '127e6fbfe24a750e72930c';
if (timingSafeCompare(sessionToken, givenToken)) {
console.log('good token');
} else {
console.log('bad token');
}
```
##License:
[MIT](LICENSE)
**Credits to:** [@jsha](https://github.com/jsha) |
[@bnoordhuis](https://github.com/bnoordhuis) |
[@suryagh](https://github.com/suryagh) |
|