3 ms·
Ah, yes, that makes sense. I was considering the case where the attacker simply wants access to your account on 'compromised system x' -- not where they're simp
by jerhinesmith 15y ago
Ah, yes, that makes sense. I was considering the case where the attacker simply wants access to your account on 'compromised system x' -- not where they're simply using 'compromised system x' as a conduit for obtaining your password (in the hopes that it's used elsewhere across the web).
Thanks!
- Johngibb 15y agoThe other issue is that the former can be done without the affected user knowing it. If a attacker resets your password, you're going to know right away when you can't log in.