Skip to content

Commit 6500a1b

Browse files
More references in NonConstantTimeCryptoComparison.qhelp
1 parent 860e8f3 commit 6500a1b

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

java/ql/src/experimental/Security/CWE/CWE-208/NonConstantTimeCryptoComparison.qhelp

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,14 @@ The next example uses a safe constant time algorithm for comparing MAC:
3737
Wikipedia:
3838
<a href="https://en.wikipedia.org/wiki/Timing_attack">Timing attack</a>.
3939
</li>
40+
<li>
41+
Coursera:
42+
<a href="https://www.coursera.org/lecture/crypto/timing-attacks-on-mac-verification-FHGW1">Timing attacks on MAC verification</a>
43+
</li>
44+
<li>
45+
NCC Group:
46+
<a href="https://www.nccgroup.trust/globalassets/our-research/us/whitepapers/TimeTrial.pdf">Time Trial: Racing Towards Practical Remote Timing Attacks</a>
47+
</li>
4048
<li>
4149
Java API Specification:
4250
<a href="https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/security/MessageDigest.html#isEqual(byte[],byte[])">MessageDigest.isEqual() method</a>

0 commit comments

Comments
 (0)