On 8/26/2021 5:35 AM, d0 wrote:
Don't forget to use CRYPTO_memcmp for comparing the HMACs, not regular ol' memcmp.
What's the rationale? The HMAC result isn't secret.
On 8/26/2021 5:35 AM, d0 wrote:
Don't forget to use CRYPTO_memcmp for comparing the HMACs, not regular ol' memcmp.
What's the rationale? The HMAC result isn't secret.