HomePhabricator

Don't reveal whether password is <20 or >20 characters in RPC
01094bd01f5dUnpublished

Unpublished Commit ยท Learn More

Repository Importing: This repository is still importing.

Description

Don't reveal whether password is <20 or >20 characters in RPC

As discussed on IRC.

It seems bad to base a decision to delay based on the password length,
as it leaks a small amount of information.

Details

Provenance
Wladimir J. van der Laan <laanwj@gmail.com>Authored on Aug 19 2014, 12:40
deadalnixPushed on May 14 2017, 22:04
Parents
rABCdd2819701a1a: Merge pull request #4670
Branches
Unknown
Tags
Unknown

Event Timeline

Wladimir J. van der Laan <laanwj@gmail.com> committed rABC01094bd01f5d: Don't reveal whether password is <20 or >20 characters in RPC (authored by Wladimir J. van der Laan <laanwj@gmail.com>).Aug 19 2014, 12:40