Skip to content

Timing attacks for email enumeration #112

Open
@neilbags

Description

@neilbags

Does this library have any protection or mitigation against email address enumeration?

With PASSWORDLESS_REGISTER_NEW_USERS set to False, and emails sent synchronously, I would expect the response time to be higher for a registered vs an unregistered user. This type of attack may also be possible even if email is sent asynchronously.

If not does anyone have a clean way to mitigate email enumeration while using this library?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions