4 ms·
Everyone who down voted this: 1) I know this would NEVEEERRRRRRR happen, but if there was a website that didn't hash a password, the timing attack would be app
by squigs25 12y ago
Everyone who down voted this:
1) I know this would NEVEEERRRRRRR happen, but if there was a website that didn't hash a password, the timing attack would be applicable.
2) It worth mentioning that a timing attack can be frequently foiled if hashing is used on the server side. I.E. Google gives me an API key, stores the hash on there side. I send the API key to Google they hash it and ocmpare the hash to their stored hash.
I think it's crazy how fat fingered people have become with the down vote trigger finger. I think it's 100% crazy to discus the timing attack without considering how it could be thwarted.