4 ms·
This is assuming that the service allows new users to sign up themselves. Also, testing it via signup sends a lot of emails to the victim (if the attacker tries
by dubbel 4y ago
This is assuming that the service allows new users to sign up themselves.
Also, testing it via signup sends a lot of emails to the victim (if the attacker tries a number of services), so the victim at least knows that something is up.
- allknowingfrog 4y agoThat was my first thought as well. The application that I maintain is invitation-only, so I think the rest of the argument is irrelevant to me.
- ohbtvz 4y agoI'm not sure what this brings to the conversation. I don't develop any web application, so the rest of the argument is also irrelevant for me. Should I broadcast that everywhere?
- mjochim 4y agoIt brings to our attention that there is a whole class of applications - "invite only" ones - where the main argument of the article does not apply. And therefore the conclusion ("The login user interface should distinguish bad user handle vs bad password") does not apply either. The article just mentions "99.9% of all websites" somewhere near the beginning, and that number may be way too high. I would in fact be interested in an analysis of how many web sites do and don't follow recommendations like "do NOT distinguish bad user handle vs bad password", which are widely considered best practices. I wouldnt take a guess, could be anywhere between 10 and 90 percent.