#sqlhmac

PrecisionSQLPrecisionSQL
2026-01-20

What's wrong with this SQL hmac check?

What's wrong with this SQL HMAC check in a webhook table. The SQL code compares signatures with a non constant time check in application logic. In SQL backed services this allows timing attacks.

...

youtube.com/watch?v=KSULCDHQW58

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst