@jeder when either the name or the password is wrong, the correct behaviour is to insert a randomised delay, otherwise the attacker can use it to check for valid usernames (pw hash is quite slow to compute so you know the name exists by how long it took)