Skip to content

Conversation

awrreny
Copy link

@awrreny awrreny commented Aug 21, 2025

This PR clarifies the section "A Note on Timing Attacks" in README.md
The original wording was confusing regarding why bcrypt is time-safe despite the comparison function not being time-safe (see issue #956 )

I also considered noting that an attacker could theoretically gain some information (the first 1-2 bytes of the stored hash) with brute force, but decided to stick with the original security claim that there is no information leaked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant