3 ms·
> Can you point to an example of a (nontrivial) site where a DoS attack against the password hashing service was the primary point of failure? Here's a vulnera
by grw_ 9y ago
> Can you point to an example of a (nontrivial) site where a DoS attack against the password hashing service was the primary point of failure?
Here's a vulnerability report from the Django framework where arbitrarily-large passwords could be submitted for checking, tying up server resources in a DoS attack: https://www.djangoproject.com/weblog/2013/sep/15/security/ https://www.djangoproject.com/weblog/2013/sep/15/security/
I'm not sure any real-world sites were affected by this, but had the patch not been applied it certainly would have been possible.