Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk3 min

Token Timing Attacks: How to Compare Secrets Safely

An early-exit equality check can leak how much of a token matches. Use a documented constant-time API and review length handling and the full authentication path.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An ordinary equality check can reveal how much of a secret token matches an attacker’s guess if it stops at the first differing character. Repeated observations may let an attacker infer a matching prefix. Use a documented constant-time comparison for secrets, handle length differences deliberately, and review the whole authentication path—not just the final comparison.

How a token check can leak a matching prefix

Many ordinary string or byte comparisons stop as soon as they find a mismatch. If the first character differs, the check can finish sooner than when several initial characters match. That makes response time potentially dependent on the position of the first mismatch.

As an Amazon Associate I earn from qualifying purchases.

With repeated guesses and a measurable timing difference, an attacker may use that signal to infer a token prefix and extend it progressively. Deno’s documentation describes the risk plainly: “By timing many requests, an attacker can recover a secret one byte at a time.” MITRE catalogs this class of weakness as CWE-208, Observable Timing Discrepancy, including examples of password checks and HMAC comparisons that stop at a mismatch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is a possible side channel, not proof that every remote token check is exploitable. Whether an attacker can distinguish the timing signal depends on the implementation and runtime environment; the cited guidance establishes no universal success rate or request count.

#1 Best Overall

Use a constant-time comparison for secret values

For authentication tokens, HMACs, tags, digests, and other secret material, use a vetted constant-time or fixed-time comparison API documented for your language, runtime, or cryptographic library. Avoid ordinary short-circuiting equality for these values, and do not replace a maintained API with a hand-written loop unless there is a strong reason and you can verify its behavior.

Cloudflare’s Workers documentation explains that equality operators such as == and === stop at the first mismatched character. Its timingSafeEqual example demonstrates a platform-specific alternative. The exact API and guarantees differ across platforms, so check the current documentation for the environment you deploy.

Check input lengths without creating another leak

Some constant-time APIs accept only equal-length inputs. A separate fast return when lengths differ can disclose length information if the secret’s length is meant to remain confidential. The comparison routine’s behavior for equal-length inputs does not automatically protect an earlier length check.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare Workers

Cloudflare documents crypto.subtle.timingSafeEqual for equal-length ArrayBuffer or TypedArray values. It says the function is not constant-time with respect to input length and advises encoding strings to bytes. Its example handles unequal lengths by still performing a comparison rather than immediately returning. Follow the current API documentation carefully: this is a Workers-specific pattern, not a guarantee that the same approach works with other APIs. The page was marked last updated April 23, 2026.

Deno

Deno’s constant-time comparison example uses same-length buffers and warns that a mismatch in raw-secret lengths may leak timing information. Confirm the current function signature and its constraints before adapting the example.

Do not add an early length-mismatch return when length confidentiality matters. If lengths are public by design, the risk calculation may differ, but the code should still follow the selected API’s documented input requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Review the whole authentication route

A constant-time final comparison does not make every operation leading up to it constant-time. Parsing, decoding, validation, length handling, error paths, or surrounding response work may still behave differently in observable ways. Cloudflare explicitly cautions that its API’s guarantee does not cover surrounding code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Find comparisons of authentication material across the full route, including tokens, HMACs, tags, and digests.
  • Check whether input is converted to bytes or typed buffers as required by the API.
  • Inspect length checks, parsing, error handling, and response behavior for distinguishable paths.
  • Verify constant-time behavior in the environment where the code will actually run.

Intel’s software security guidance states: “For any code that you write—whether C or hand-coded assembly—you must verify constant-time operation in the environment where you expect to use it.”

HMAC checks need the same care

HMAC validation is also a secret-dependent comparison. OWASP’s Cross-Site Request Forgery Prevention Cheat Sheet specifically recommends using a constant-time equality function when comparing HMAC values. Apply the API’s input and length requirements to the HMAC check just as you would to a token comparison.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.