Authentication-Results: mail-b.sr.ht; dkim=pass header.d=gpanders.com header.i=@gpanders.com Received: from relay8-d.mail.gandi.net (relay8-d.mail.gandi.net [217.70.183.201]) by mail-b.sr.ht (Postfix) with ESMTPS id BB42211EF27 for <~sircmpwn/sr.ht-discuss@lists.sr.ht>; Tue, 18 May 2021 21:45:22 +0000 (UTC) Received: (Authenticated sender: greg@gpanders.com) by relay8-d.mail.gandi.net (Postfix) with ESMTPSA id F38E11BF203; Tue, 18 May 2021 21:45:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gpanders.com; s=gm1; t=1621374321; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=slcL+0bEQwwFLVBADmP/Pfo/QbebiHkvoCWMgM/Vmw8=; b=pzDqQfXFpXUyKzOAc0EX3dEP2+sg6SNzX9TuzdWoi9sRW0p1xAlDIjQ8/L68vJNNWyVARV /qmY22V+xqMB9mdWe/2wj+jlk1e4FE0/iLknMAp6XxrROIrxoKWKi+y/AWOhx1y/VheFqE KGaF56W69X97+KgAUdtKdcxvw/kB0fxvazUyuWnNcQVqG3hiMnZCLVhsxkb9ZLNsnUHGT4 dNrthT76oda/WPryIUg4n+S7ANPj8EUXU8aL9qQidbv9ru0ZM6qxAqWvYgZC4bPITmqrMb a+4ArfFZOETRmWtDDc5iODJf8Ys1nBI86omiKNhslKO9/h0Vf01z2HJ7ka1DKg== Date: Tue, 18 May 2021 15:45:17 -0600 From: Gregory Anders To: Sebastian LaVine Cc: ~sircmpwn/sr.ht-discuss@lists.sr.ht Subject: Re: Should private repositores show 404 instead of 401? Message-ID: References: <20210518203551.tnsbe6hmugxn64sr@iyo> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Disposition: inline In-Reply-To: On Tue, 18 May 2021 16:50 -0400, Sebastian LaVine wrote: >I do not know what these are, and would appreciate it if someone were >to explain them for me. You can measure the time difference between a page that *actually* doesn't exist and a page that does exist but the server returns a 404 for. Wikipedia has a good page on this [1]. [1]: https://en.wikipedia.org/wiki/Timing_attack