Don't reveal whether password is <20 or >20 characters in RPC #4728

pull laanwj wants to merge 1 commits into bitcoin:master from laanwj:2014_08_rpcserver_password_delay changing 1 files +2 −3
  1. laanwj commented at 12:48 PM on August 19, 2014: member

    As discussed on IRC.

    It seems bad to base a decision to delay on the password length, as it leaks a tiny bit of information.

    This doesn't change DoS potential as it is trivial to hold up all RPC threads in another way for someone in the rpcallowip list.

  2. Don't reveal whether password is <20 or >20 characters in RPC
    As discussed on IRC.
    
    It seems bad to base a decision to delay based on the password length,
    as it leaks a small amount of information.
    01094bd01f
  3. laanwj added the label RPC on Aug 19, 2014
  4. BitcoinPullTester commented at 1:01 PM on August 19, 2014: none

    Automatic sanity-testing: PASSED, see http://jenkins.bluematt.me/pull-tester/p4728_01094bd01f5d999b7da698c0e655cf723afa8ebb/ for binaries and test log. This test script verifies pulls every time they are updated. It, however, dies sometimes and fails to test properly. If you are waiting on a test, please check timestamps to verify that the test.log is moving at http://jenkins.bluematt.me/pull-tester/current/ Contact BlueMatt on freenode if something looks broken.

  5. gavinandresen commented at 1:31 PM on August 19, 2014: contributor

    Untested ACK

  6. jgarzik commented at 1:59 PM on August 19, 2014: contributor

    ut ACK

  7. gavinandresen referenced this in commit 10dcbc1be0 on Aug 19, 2014
  8. gavinandresen merged this on Aug 19, 2014
  9. gavinandresen closed this on Aug 19, 2014

  10. MarcoFalke locked this on Sep 8, 2021

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-04-13 15:15 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me