4 ms·
Hi, interested in the above comment. Can you explain how a timing attack would work here?
by al_james 14y ago
Hi, interested in the above comment. Can you explain how a timing attack would work here?
- lucian1900 14y agoAn interesting demo: [1] By not doing all 3 hashes, an attacker might realise that the password they sent passed, say, 2 checks, but not the third. This discloses information about the relationship between the password the attacker just tried and the correct password. [1] http://carlos.bueno.org/2011/10/timing.html http://carlos.bueno.org/2011/10/timing.html
- furyofantares 14y agoI'm not sure how this is applicable here, if the attacker passes any of the tests then they are able to log in
- lucian1900 14y agoIndeed, stupid logic on my part.
- nooooooo 14y agoAnd that relationship is useful how?
- al_james 14y agoI see the problem in theory, but in reality, the time of a couple of hash functions compared to network latency and application server routing would be quite small. Can timing attacks actually work in such situations?