KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
It seems that for a while , the login utility on Unix systems only calculated a hash when a valid username existed; this opened a security flaw which allowed for a timing attack, as the user could tell when a username was found by the amount of time it required to generate hashed key for comparison. This makes sense for desktop applications, but would it make sense for web applications too? I'd lean toward doing it, but is this kind of fix necessary? For example, in a Django auth module: class MyBackend(ModelBackend): def authenticate(self, email=None, password=None): try: user = User.objects.get(email=email) return user if user.check_password(password) else None except User.DoesNotExist: User().check_password(password) # is this line necessary? return None Would the additional hash computation make sense for this scenario? If I employ rate-limiting on auth calls, does this decrease the possibility of a timing attack like this?
Tags (comma-separated)
Save Edits
Cancel