|
|
|
|
|
by hinkley
2346 days ago
|
|
Do you suppose there's a timing attack where someone can figure out if any particular users (target user, or admins) are currently online and get up to nonsense if they aren't? Not sure if your app is big enough to care, but it might be you want to normalize the response times, so server load is reduced but auth time is fixed. |
|
I don't work on that anymore though. I might do something similar in the future, but being able to detect when admins are snoozing is low on my list of concerns; if it's designed properly, it'll be cheaper to hire PIs to just look and see when they're snoozing.