3 ms·
Not sure if sarcasm..
by broolstoryco 13y ago
Not sure if sarcasm..
- nfm 13y agoThis is a real attack vector. It's called a timing attack: http://en.wikipedia.org/wiki/Timing_attack http://en.wikipedia.org/wiki/Timing_attack
- broolstoryco 13y agoI am familiar with timing attacks. The thought of someone attempting to apply it over the internet to verify whether an email is registered on a dating site seems laughable.
- MichaelGG 13y agoApplying it over the Internet is quite feasible, especially with simple code. If it connects to a remote SMTP server, the delay may very well be noticeable enough without doing any complicated timing. It might be just about as easy as scraping the page for "user not found" versus "email sent". I assume that was the original point - that on risque dating sites, the recover password system tries to hide membership.