HMAC, integrity & timing

P52.hashing-integrity.02 · Audience: guest, it-ml, language-pro · Prerequisites: Hashing: fingerprints of data

Real LLM grading for this pageLLM grading (this page):

A hash proves data has not accidentally changed, but anyone can recompute one — it says nothing about who sent the data. This module adds authenticity with HMAC, and then closes the subtle side channel that can leak a secret even when the maths is right: comparison timing.

You will build HMAC from hashlib to see why the naive hash(key + msg) is forgeable, write a constant-time comparison, and finish on the interview rung that ties hashing, HMAC and signatures together.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — build HMAC, defeat length extension

Loading exercise…

Rung 2 — compare secrets in constant time

Loading exercise…

Interview rung — integrity in transit (free-form)

Loading exercise…

My notes on this module

Loading your notes...

HMAC, integrity & timing — TransformerLab