---
title: "authenticate_by: Prevent timing-based enumeration of users."
url: https://daily.dev/posts/authenticate-by-prevent-timing-based-enumeration-of-users--a4a1u7zjq
source_url: https://a-chacon.com/en/ruby/rails/security/2024/04/18/authenticate-by-for-prevent-timing-based-enumeration-in-rails.html
type: article
source: "Ruby Flow"
published: 2024-04-19T07:12:56.177Z
updated: 2024-05-09T09:06:09.090Z
tags: ["authentication", "rails", "web-security"]
reading_time: 3
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# authenticate_by: Prevent timing-based enumeration of users.

**[Ruby Flow](https://daily.dev/sources/rubyflow)** · 3 min read · 1 upvotes · 0 comments

## Summary

The code in the post has a security problem related to response times, which can be exploited by an enumeration attack. Rails 7.1 introduced the 'authenticate_by' method to prevent this type of attack. The method ensures consistent response times for both existing and non-existing user emails, improving web application security.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://a-chacon.com/en/ruby/rails/security/2024/04/18/authenticate-by-for-prevent-timing-based-enumeration-in-rails.html>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#authentication](https://daily.dev/tags/authentication), [#rails](https://daily.dev/tags/rails), [#web-security](https://daily.dev/tags/web-security)

[View this post on daily.dev](https://daily.dev/posts/authenticate-by-prevent-timing-based-enumeration-of-users--a4a1u7zjq)
