-
Updated
Sep 29, 2020 - PHP
user-profile
Here are 65 public repositories matching this topic...
-
Updated
Dec 7, 2020 - PHP
-
Updated
Apr 10, 2019
-
Updated
Mar 19, 2018
-
Updated
Dec 7, 2020 - PHP
-
Updated
Oct 31, 2020 - PHP
-
Updated
Nov 15, 2020 - C#
-
Updated
Oct 5, 2020 - PHP
-
Updated
Dec 7, 2020 - JavaScript
-
Updated
Aug 23, 2020 - JavaScript
-
Updated
Dec 7, 2020 - PHP
-
Updated
Nov 24, 2020 - Shell
-
Updated
May 5, 2019 - Swift
-
Updated
Aug 25, 2018 - Python
-
Updated
Dec 13, 2017 - Java
-
Updated
May 3, 2017 - JavaScript
-
Updated
Aug 21, 2020 - JavaScript
-
Updated
Aug 18, 2018 - Ruby
-
Updated
Sep 9, 2020 - JavaScript
-
Updated
Mar 2, 2018 - PowerShell
-
Updated
Oct 19, 2020 - Python
-
Updated
Nov 23, 2020 - PHP
-
Updated
Sep 26, 2020 - JavaScript
-
Updated
Jun 16, 2019 - PHP
-
Updated
May 26, 2020 - TSQL
-
Updated
Nov 28, 2020 - JavaScript
-
Updated
Jul 20, 2017 - Java
-
Updated
Dec 3, 2019 - PHP
Improve this page
Add a description, image, and links to the user-profile topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the user-profile topic, visit your repo's landing page and select "manage topics."
Describe the bug
Currently, login requests will fail faster if the user does not exist as the hash does not have to be computed. This can leave to timing attacks where an attacker can guess if a user exists or not, which defeats account enumeration defenses.
Expected behavior
Every login request should take a similar amount of time regardless of whether the user exists or not. The