5 ms·
Why? Why not just tell the user what is actually wrong?
by basdp 9y ago
Why? Why not just tell the user what is actually wrong?
- tome 9y agoBecause the application doesn't know what is actually wrong. The error message is actually correct as written. The user entered their username incorrectly or their password incorrectly, or both. The application doesn’t know which and shouldn’t guess!
- kalleboo 9y agoWhy wouldn't the application know?
- tuxxy 9y agoThe application doesn't know if the username you entered is actually yours or someone else's. You could provide the correct password to your account 'test', but not 'ttest'. The server just tells you to check both instead, it's more semantically correct and offers some security improvements with user enumeration.
- IshKebab 9y agoIt knows if it doesn't exist though. This whole thing is about sites that say "Username or password is wrong" when they know the username is wrong because it doesn't exist!
- tome 9y agoIs it? I thought it was about sites that say "Username or password is wrong" when they know the username does exist! After all, the author is using his own, correct, username in the examples!
- dagw 9y agoWhat if a username does exists, but isn't my username. Imagine both 'dave' and 'davr' have an account. I'm 'dave', but I accidentally type 'davr' and my correct password. Now the site will tell me that my password is wrong. So I retype and retype my password over and over again and still can't log in, because the problem isn't the password like the error message says, but rather that I typed the wrong my username.
- tantanel 9y agoThe message is still not wrong if you think of "or" as the boolean or, not as the boolean xor. The system knows the username is wrong but it doesn't know anything about the password.
- Brinkintrots 9y agoIt's not wrong, it's just not as helpful as it could be.
- bolololo1 9y agoThe application knows unless it some app written by someone who is starting with programming.
- gaius 9y agoHow can it? It passes the pair to some auth API and gets just a yes or a no back.
- chrisper 9y agoIf the application already knows then the person using it is already authenticated.
- endless1234 9y agoIf the username exists, how does the app know whether the user typed the wrong username or password?
- rodorgas 9y agoThis is true for existing user with wrong password, but that message would be wrong if the user doesn't exist. In this case, the error clearly would be the username, not the combination user+pass.
- deleted 9y ago[deleted]
- icebraining 9y agoHow can the pass be correct if the username isn't? A password is only correct in the context of a specific account.
- irishsultan 9y agoThe password may be correct for the user (who is a person, and has a password for that service). Of course the person may have multiple user accounts and he may have given the "wrong" password for the "right" username account, but he may also have given the "right" password for the "wrong" username.
- detaro 9y agoBecause this prompts them to check the username again, instead of trying to enter their password again while they typo'd the username (but hit a valid account with their typo)?
- 1ba9115454 9y agoBecause it allows attackers to look for accounts. It's part of your privacy that I shouldn't be able to see if you have an account with sexycatpictures.com Not accusing you BTW.
- aninhumer 9y agoRead the article. It's debunking that exact argument.
- 1ba9115454 9y agoYou read the article. Author backtracks at the end.
- IshKebab 9y agoI read it. He doesn't. Read it again. > To prevent attackers from knowing whether an account exists or not your signup must only take an email address and provide no feedback in the UI if the sign up succeeded or not. Instead the user would receive an email saying they’re signed up. The only way an attacker would know if an account exists is if they had access to the target’s email. > Barring that, “username or password incorrect” is just bullshit. What he means is the only way it would make sense is if and only if a website's account registration page responding with something like: "You tried to sign up for me@example.com. If that account didn't already exist, a registration email has been sent to it." But nobody does that! Registration pages just say "Sorry that email is already in use", which is what makes this whole thing bullshit.
- travisjeffery 9y agoExactly. You got it.
- yoodenvranx 9y agoAssume a site has two accounts "user122" and "user123". When a user logs in with "user122" and a password and it does not work: What happened? Did the user mistype the password or the username?
- IshKebab 9y agoAssume a user got their username or password wrong. What is more likely, they got their username wrong in a way that happens to be the same as another user, or they got their password wrong?
- bonzini 9y agoMost people store passwords in their browser, which already makes the answer not that obvious. For a rarely used web site, I honestly would have no idea if I registered as bonzini, pbonzini or bonzinip. Now my surname isn't particularly common, but smithj and jsmith might be easily confused.
- larzang 9y agoI have a commonish firstlast@gmail account and frequently receive what is the obvious result of people in various parts of the country incorrectly providing my email to apply for jobs, order pizzas, and use other services. It is absolutely common for users to supply the incorrect username/email.