HMAC
A keyed hash: proves a message came from someone holding the same secret.
The key stays in this page. Nothing is sent anywhere — but a production signing key is still worth being careful with.
Result
Good to know
- An HMAC is a hash of the message and a shared secret together. Anyone holding the key can produce it and check it; anyone without it can do neither — which is what makes it a signature rather than a checksum.
- It is not the same as hashing the key and the message glued together. That construction can be extended by someone who never saw the key; HMAC's two nested passes are what close that hole.
- When your own code checks an HMAC, compare the two values in constant time. A plain equality check leaks how much of the signature was right through how long it took to say no.
- The signing is done by the browser's own cryptography, in this page. Neither the message nor the key is sent to the server or stored anywhere.
30 views