4 ms·
Any evidence of this being used in the wild, particularly where the attack is only trying password variants if the initial failure indicated the user exists? No
by mnarayan01 9y ago
Any evidence of this being used in the wild, particularly where the attack is only trying password variants if the initial failure indicated the user exists? Not disagreeing with the point, just would be interesting if anyone's seen such an attack.