3 ms·
Most sites require a email address to create an account, leaving a larger footprint for forensics. The sites I work on require much more personal data that is v
by romdev 9y ago
Most sites require a email address to create an account, leaving a larger footprint for forensics. The sites I work on require much more personal data that is validated against other systems to confirm identity. Out-of-session page requests are scrutinized for patterns that look like a bad guy checking the locks.
Granted, many sites will have client side validation for passwords, but that should be considered a user convenience - not a security measure, and doesn't necessarily have to be as strict as the server side validation. New users won't 'accidentally' enter Unicode escape sequences in passwords, but we need to prevent that on the server side validation and show a generic error "your enrollment failed for some reason" so the bad guy doesn't know if it's input validation or personal data validation that failed.