2

The documentation for PHP’s hash_equals() (a string comparison function which is safe from timing attacks) says,

It is important to provide the user-supplied string as the second parameter, rather than the first.

Why is this?

2

0

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.