Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent timing attacks on authentication #239

Merged
merged 2 commits into from
Aug 4, 2019
Merged

Conversation

danschultzer
Copy link
Collaborator

Resolves #238

This is ready to merge, but I may add more to it as I still have to review the whole repo to see if there are other places that has timing attack vulnerability.

@danschultzer danschultzer mentioned this pull request Jul 18, 2019
@danschultzer
Copy link
Collaborator Author

Only found one more potential vulnerability in the the reset password plug extension.

@danschultzer danschultzer merged commit f0fc5f0 into master Aug 4, 2019
@danschultzer danschultzer deleted the prevent-timing-attack branch August 4, 2019 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Timing attacks
1 participant