Socket
Socket
Sign inDemoInstall

buffer-equal-constant-time

Package Overview
Dependencies
0
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

buffer-equal-constant-time

Constant-time comparison of Buffers


Version published
Maintainers
1
Weekly downloads
14,526,400
decreased by-7.44%

Weekly downloads

Package description

What is buffer-equal-constant-time?

The buffer-equal-constant-time npm package is used to check if two buffers are equal without leaking timing information that could be used to infer the contents of the buffers. This is particularly useful for preventing timing attacks when comparing sensitive data, such as cryptographic hashes or tokens.

What are buffer-equal-constant-time's main functionalities?

Constant-time buffer comparison

This feature allows for the comparison of two buffers in a way that the time taken to compare them does not depend on the number of bytes that match. This is important for security purposes to prevent timing attacks.

const bufferEqualConstantTime = require('buffer-equal-constant-time');
const buffer1 = Buffer.from('sensitive data');
const buffer2 = Buffer.from('sensitive data');
const isEqual = bufferEqualConstantTime(buffer1, buffer2); // returns true if equal, false otherwise

Other packages similar to buffer-equal-constant-time

Readme

Source

buffer-equal-constant-time

Constant-time Buffer comparison for node.js. Should work with browserify too.

Build Status

  npm install buffer-equal-constant-time

Usage

  var bufferEq = require('buffer-equal-constant-time');

  var a = new Buffer('asdf');
  var b = new Buffer('asdf');
  if (bufferEq(a,b)) {
    // the same!
  } else {
    // different in at least one byte!
  }

If you'd like to install an .equal() method onto the node.js Buffer and SlowBuffer prototypes:

  require('buffer-equal-constant-time').install();

  var a = new Buffer('asdf');
  var b = new Buffer('asdf');
  if (a.equal(b)) {
    // the same!
  } else {
    // different in at least one byte!
  }

To get rid of the installed .equal() method, call .restore():

  require('buffer-equal-constant-time').restore();

© 2013 GoInstant Inc., a salesforce.com company

Licensed under the BSD 3-clause license.

Keywords

FAQs

Last updated on 16 Dec 2013

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc