4 ms·
As far as I'm aware, there's an attack where you can determine how correct a password is based on how long it takes to get denied. For example, take a simple al
by landa 5y ago
As far as I'm aware, there's an attack where you can determine how correct a password is based on how long it takes to get denied. For example, take a simple algorithm where you check the password character by character, and return as soon as you encounter a bad character. This means you can detect a subset of a correct password.