Response time of authentication probes should be indistinguishable whether an user exists or not.
This requirement aims to ensure that, regardless of the input or conditions, the response time of a system remains indistinguishable. By carefully measuring response times, an attacker may infer details about the internal operations of a system, and maybe exposing sensitive information.
This requirement is verified in following services
Plan | Supported |
---|---|
Essential | 🔴 |
Advanced | 🟢 |