Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Think memcmp is safe? Think again (github.com/stateless-me)
2 points by aabbdev 76 days ago | hide | past | favorite | 1 comment


Shipped a timing leak via early-exit memcmp + secret branch. Flatline is a single-header toolbox for constant-time C (CT compare/select/lookup/div) guided by B.I.D.—no Branch on secrets, no secret Index, no variable-latency ops. DUDECT tests; feedback on LTO/autovec welcome




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: