Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah could the DB token lookup timings by itself be used to find a real token? It might be several layers deep and DBs are noisy, but I think it's still possible in theory. Could you get around this by only storing some hash of both the token and a DB secret?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: