3 ms·
Yes and Yes (assuming your random key isn't guessable). breachattack.com suggests masking the secret with a per-request random key, but masking the user input
by strommen 11y ago
Yes and Yes (assuming your random key isn't guessable).
breachattack.com suggests masking the secret with a per-request random key, but masking the user input would work too.