Skip to content

How long before a challenge is brute forced? #14

Closed Answered by dagnelies
lil5 asked this question in Q&A
Discussion options

You must be logged in to vote

So, just to be clear, the challenge is just a random value, in our case with 18 bytes / 144 bit of entropy by default.

If the attacker has eavesdropped an authentication payload, and wants to "repeat" the login using the same payload, hence the same challenge, he would have to send on average roughly 10^43 requests to your server ...that's a lot of zeroes.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by lil5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants