HMAC, integrity & timing
P52.hashing-integrity.02 · Audience: guest, it-ml, language-pro · Prerequisites: Hashing: fingerprints of data
A hash proves data has not accidentally changed, but anyone can recompute one — it says nothing about who sent the data. This module adds authenticity with HMAC, and then closes the subtle side channel that can leak a secret even when the maths is right: comparison timing.
You will build HMAC from hashlib to see why the naive hash(key + msg) is
forgeable, write a constant-time comparison, and finish on the interview rung
that ties hashing, HMAC and signatures together.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — build HMAC, defeat length extension
Loading exercise…
Rung 2 — compare secrets in constant time
Loading exercise…
Interview rung — integrity in transit (free-form)
Loading exercise…
My notes on this module
Loading your notes...
Where next?
This module unlocks