User avatar
Jeder neocat_floof_googly_woozy neocat_flag_agender @jeder@miau.jeder.pl
1y
can software stop doing this thing where they are processing invalid passwords way longer than valid ones
4
6
12
0
User avatar
Piggo ➡️ gs.rypak.cz @piggo@piggo.space
1y
@jeder when either the name or the password is wrong, the correct behaviour is to insert a randomised delay, otherwise the attacker can use it to check for valid usernames (pw hash is quite slow to compute so you know the name exists by how long it took)
1
0
0
0
User avatar
Jeder neocat_floof_googly_woozy neocat_flag_agender @jeder@miau.jeder.pl
1y
@piggo yeah like imo both valid and invalid uses should have a delay
1
0
0
0

User avatar
Piggo ➡️ gs.rypak.cz @piggo@piggo.space
1y
@jeder when its valid you dont have to pretend anything anymore
0
0
0
0