Skip to content

Investigation: Check and potentially fix timing attack vulnerability in pwreset #2352

Description

@andrewtavis

Terms

Issue

Based on discussion in the work for #1864, we want to actually test the timing of the pwreset method to see what the difference is when a user does and does not exist. Ideally these would be very similar, and if the non-existing user is leading to a consistently lower response time, then we'd make changes to backend/authentication/views.py to fix this :)

Metadata

Metadata

Assignees

Labels

-priority-High prioritybackendRelates to the project backendpythonRelates to Python code

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions