From 6f59ff07a317409fe68696935daf8549b1555c74 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sybren=20A=2E=20St=C3=BCvel?= Date: Mon, 26 Oct 2020 15:36:20 +0100 Subject: [PATCH] Add URL with more info to timing security issues --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 875c7f6..2684060 100644 --- a/README.md +++ b/README.md @@ -26,7 +26,7 @@ licensed under the [Apache License, version 2.0](https://www.apache.org/licenses Security -------- -Because of how Python internally stores numbers, it is very hard (if not impossible) to make a pure-Python program secure against timing attacks. This library is no exception, so use it with care. +Because of how Python internally stores numbers, it is very hard (if not impossible) to make a pure-Python program secure against timing attacks. This library is no exception, so use it with care. See https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/ for more info. Major changes in 4.1