3 ms·
Not an expert, but from what I understand, many of these attacks rely on being able to make LOTS of attempts (on order of thousands/millions). Any factor which
by ryebit 9y ago
Not an expert, but from what I understand, many of these attacks rely on being able to make LOTS of attempts (on order of thousands/millions). Any factor which doesn't correlate directly to the username & password inputs should approach a constant as the sample size grows, since it's timing distribution (by definition) isn't affected by changes in the user/password inputs. This is especially true of things like adding a random amount of delay.
That said, I'm curious as to how well that plays out in the real world, particularly over a noisy connection.
---
But if it is feasible, the best method to defeat it is probably rate-limiting. That then gets tricky. You can rate limit on username alone, IP address alone, or a complex derivative of them (e.g. to detect botnets). But all those approaches introduce their own DDOS and scalability issues.