6 ms·
If you have an index on your "Email" field in the database, there may be discernible difference between the time taken to check the index and return '0 rows', v
by shabble 12y ago
If you have an index on your "Email" field in the database, there may be discernible difference between the time taken to check the index and return '0 rows', vs getting a match and actually reading the appropriate data to build the result row.
I don't know if there's a solution to that in the general scheme of things, other than making the variance of query times between no user and some user as small as possible.
- tracker1 12y agoAnd, if you're returning the correct error message, it doesn't matter.. the whole point of a timing attack is to determine the difference. IMHO usability is more important. There are other ways to improve security. Rate limiting with < N failed attempts via an IP in under < X minutes.