Github的安全webhooks页面说:
==不建议使用普通运营商.一种方法,例如secure_compare执行"常量时间"字符串比较,这使得它对于针对常规相等运算符的某些定时攻击是安全的.
==
secure_compare
我bcrypt.compare('string', 'computed hash')在比较密码时使用.
bcrypt.compare('string', 'computed hash')
是什么使这成为"安全比较",我可以使用cryptoNode中的标准库吗?
crypto
security cryptography node.js
cryptography ×1
node.js ×1
security ×1