Do we need to put the password in the cache key?
key = anyhash(uuid+username)
if (result := cache.get(uuid+username)):
if hash_and_equality(password, result.password_hash):
return result.the_other_stuff
# try login or else failOf course, if you have any validness of old sessions / passwords around a password change, you are doing something wrong.
My personal wondering is, considering KDF is meant to be expensive, why is IO more expensive to the point it needs a cache?
> why is IO more expensive to the point it needs a cache
The advisory mentions it's only exploitable if the upstream auth server is unresponsive. So it seems to be mainly for resilience.
At least that's my immediate thought, could be wrong.