Skip to content

Sign In: Timing Attack #1544

Answered by pilcrowOnPaper
rwieruch asked this question in Q&A
Discussion options

You must be logged in to vote
  1. I don't think you need to generate a random password with each attempt. An empty string will do.
  2. Do you really need to hide the username or email? Usernames are usually public info and the validity of emails can usually be checked with the registration form.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@rwieruch
Comment options

Answer selected by rwieruch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants