TE
科技回声
首页
24小时热榜
最新
最佳
问答
展示
工作
中文
GitHub
Twitter
首页
Tips for finding security issues in GitHub projects
115 点
作者
geekrax
超过 7 年前
3 条评论
latchkey
超过 7 年前
Collapse
Thanks for sharing! Seems like a company that does this as an automated service (for private orgs/repos) would be $.
评论 #15422734 未加载
_asummers
超过 7 年前
Collapse
What does the author mean about timing attacks on HMACs with Array.equals? Does HMAC leak info and is it subject to timing attacks if you HMAC on both sides before doing equality checks? Does he mean for e.g. session cookies?
评论 #15423647 未加载
reconbot
超过 7 年前
Some of the links are bad but this is a great list of things to keep in mind when seeing where your work is with regards to security.