Hey westin!

Yeah, my first thoughts on mitigation was have the password submitted in its entirety and check it in its entirety before giving a virtually identically similar response time reply.

My thinking was to look at the % of error............humans won't make that high a %?.............a typo, transposition error or something like that?

Then you will know if you have an attack.