3 ms·
>tampered logins need not show up as failures. Thanks for clarifying it. Yes, the writing about it is surprisingly unclear. Even on the original paper and the
by herendin 4y ago
>tampered logins need not show up as failures.
Thanks for clarifying it. Yes, the writing about it is surprisingly unclear. Even on the original paper and the dedicated website for this bug, there's a frustrating lack of clarity about what they mean by "login" and how much the user is in the loop of this attack, which could be an important gating factor making it unlikely to ever have been a practical exploit