3 ms·
The point is this exploit, according to the researchers, required massive and unusual manual intervention by the user, so it's very different from the other exp
by herendin 4y ago
The point is this exploit, according to the researchers, required massive and unusual manual intervention by the user, so it's very different from the other exploit you mentioned that involves millions of auth attempts
From the link I just posted, written by the researchers:
'Nevertheless, on the clients that we analyzed, all attacks would have required a substantial number of manual login attempts (i.e., the user entering the password). Since clients usually cache the credentials, users often stay logged in, minimizing the number of logins performed and thereby increasing the difficulty of the attacks.'