Comment 1 for bug 1175906

Revision history for this message
Thierry Carrez (ttx) wrote : Re: passlib long password DoS

This one is slightly more borderline, although I'm not convinced you could drive a DoS from it -- some valid keystone actions already take more than 2 seconds and hit I/O harder than this... so your stack has to survive those kind of requests anyway.

Adding the keystone core team so that we get their opinion on this.

(it's also a painful fix, because you don't want to break hypothetical long passwords on upgrades)