4 ms·
Yes, it is.
by ToastOpt 15y ago
Yes, it is.
- polymatter 15y agoso you can simply have a maximum delay, of say 10 minutes.
- jtreminio 15y agoIf you had to wait 10 minutes to login to a website every time, you'd very quickly stop bothering to log in.
- viscanti 15y agoYou'd rule out all the legitimate users and only be left with people trying to break in. That strategy would only work on a honey-pot site.
- Retric 15y ago10 minutes +1ms vs 10minutes +2ms can still leak information. Ideally you want something like 3 seconds per password per IP starting the timer before you look up the password.