> They won’t teach you that in your /login endpoint, if a user is not found, you should verify the password against a pre-computed dummy hash so the response delay matches a real user account workflow to avoid timing attacks. You only learn this on the job under the supervision of a senior mentor.
Actually this kind of timing attacks were taught to me in information security and cryptography class, alongside other side channel attacks.