How 7-Zip Prevents Side-Channel Timing Attacks
7-Zip protects password verification against side-channel timing attacks by eliminating direct password string comparisons and utilizing computationally intensive key derivation combined with structural integrity checks. Instead of checking a user’s input against a stored hash character by character, 7-Zip relies on an iterative SHA-256 derivation process to generate an AES-256 decryption key, ensuring that verification time does not leak information about password accuracy.
Iterative Key Derivation
When a password is submitted, 7-Zip processes it using a key derivation function based on SHA-256. By default, 7-Zip runs this hashing routine through \(2^{19}\) (524,288) iterations to generate the 256-bit AES encryption key.
This heavy derivation process mitigates timing attacks in two distinct ways:
- The Avalanche Effect: Changing even a single character in the password completely scrambles the resulting output. An attacker cannot incrementally verify individual characters because the derived key changes entirely with any variation.
- Timing Uniformity: The computation time for the key derivation function depends strictly on the fixed number of iterations, not on the validity or composition of the password. The cycle count remains identical whether the guess is completely wrong or completely correct.
Absence of Stored Password Hashes
Traditional timing attacks exploit functions like strcmp
or memcmp, which often terminate early upon encountering
the first non-matching byte. 7-Zip avoids this vulnerability entirely
because 7z archives do not store a password hash or an authentication
token against which the user's input is directly matched.
Because there is no target hash stored in the archive metadata, there is no byte-by-byte comparison operation to measure.
Decryption-Based Verification
Instead of validating a hash, 7-Zip verifies a password by attempting to decrypt the data. The derived AES-256 key is applied to decrypt either the archive header (if header encryption is enabled) or the compressed file streams.
Password correctness is evaluated through:
- Header Parsing: If the key is correct, the decrypted block yields valid 7z header markers and structural metadata. If the key is incorrect, the output is indistinguishable from random noise, causing the header parser to fail.
- CRC Integrity Checks: For archives without encrypted headers, 7-Zip decrypts the file payload and calculates its CRC32 checksum. If the calculated checksum does not match the stored CRC, 7-Zip reports a wrong password or data error.
Because decryption and checksum algorithms process entire data blocks uniformly, an attacker cannot measure microsecond differences to deduce partial password correctness. The operation must complete the full derivation and cryptographic block cycle before failing, neutralizing timing as an attack vector.