mirror of
https://github.com/btcsuite/btcd.git
synced 2024-11-19 09:50:08 +01:00
Mitigate timing attacks while using btcec.Decrypt.
This commit is contained in:
parent
9d6d0e4006
commit
d9556df292
@ -178,7 +178,7 @@ func Decrypt(priv *PrivateKey, in []byte) ([]byte, error) {
|
|||||||
hm := hmac.New(sha256.New, keyM)
|
hm := hmac.New(sha256.New, keyM)
|
||||||
hm.Write(in[:len(in)-sha256.Size]) // everything is hashed
|
hm.Write(in[:len(in)-sha256.Size]) // everything is hashed
|
||||||
expectedMAC := hm.Sum(nil)
|
expectedMAC := hm.Sum(nil)
|
||||||
if !bytes.Equal(messageMAC, expectedMAC) {
|
if !hmac.Equal(messageMAC, expectedMAC) {
|
||||||
return nil, ErrInvalidMAC
|
return nil, ErrInvalidMAC
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user