DEV Community

Nadim Chowdhury
Nadim Chowdhury

Posted on

This Tiny Code Review Mistake Can Leak Your HMAC Secrets

Here is a subtle security bug that still passes code review in many codebases:

// Vulnerable to timing attacks
if (receivedHmac === computedHmac) {
  return grantAccess();
}
Enter fullscreen mode Exit fullscreen mode

Standard string comparison in most languages short-circuits. As soon as the first non-matching character is encountered, the comparison returns false.

By measuring the exact execution time down to nanoseconds across thousands of requests, an attacker can guess the HMAC signature byte by byte.

The fix is constant-time comparison:
Comparing every byte regardless of whether an earlier byte mismatched, ensuring execution time reveals zero information.

WebCrypto handles this constant-time verification automatically under the hood.

Test HMAC generation and validation:
https://utilifi.vercel.app/tools/security/hmac-generator

Top comments (0)