Uploaded image for project: 'JOC - JobScheduler Operations Center'
  1. JOC - JobScheduler Operations Center
  2. JOC-1615

It should not be possible to guess known accounts from the response time of a failed login

    XMLWordPrintable

Details

    Description

      Current Situation

      A login with an unknown account takes less time than a login with a known account.

      Such disparities in response times for authentication attempts could allow attackers to guess valid user accounts. Armed with this knowledge they might subsequently launch brute-force attacks for credentials of valid accounts to achieve unauthorized access to JOC Cockpit.

      Desired Behavior

      Failed logins should enforce random delays.

      • First and second failed login: delay between 1s and 3s
      • Third and more failed logins: delay between 25s and 35s

      A successful login resets the counting.

      Attachments

        Activity

          People

            ur Uwe Risse
            ur Uwe Risse
            Kanika Agrawal Kanika Agrawal
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: