Network Service Authentication Timing Attacks
Adrian Hayes · IEEE Security & Privacy · 2013
The common wisdom is that string comparison timing attacks against a hashed password are impossible. However, these attacks can still be effective if attackers give up on the ideal of stealing all the characters representing the user's password or the entire hash.