This repository was archived by the owner on Oct 25, 2024. It is now read-only.
This repository was archived by the owner on Oct 25, 2024. It is now read-only.
What about timing attacks? #4
Open
Description
I see code in authenticate() function on this form:
if (something)
raise FAILED
if (something_else)
raise FAILED
This might make it possible to time where in the process the error was detected. Is it perhaps better to do something like this:
if (something)
error = True
if (something_else)
error = True
if (error)
raise FAILURE
Or is it not needed for other reasons related to for example django?
Metadata
Metadata
Assignees
Labels
No labels