3 ms·
The article makes a good point, were it not for security auditors (SAs). SA: You leak information and therefore violate policy by disclosing on the login form
by MostlyInnocent 4y ago
The article makes a good point, were it not for security auditors (SAs).
SA: You leak information and therefore violate policy by disclosing on the login form whether an account exists or not!
Me: Yeah, but figuring out if an account exists is really simple anyway: just a query to a different endpoint...
SA: NEVERMIND, MY LAD: disclosing account existence upon login violates BEST PRACTICES!
Me: OK, yeah, whatever, we'll just change the error message to "something you may or not have entered may or may not be valid information, try again, or not"
SA: cool beans! WE ARE NOW INDUSTRY LEADERS
- Terretta 4y agoEvery well known credit card / credit data breach has been of a PCI-DSS compliant party. To any SAs reading this: you're not secure because you're compliant.
- mcv 4y agoThe big issue there is that they store credit card data at all. And of course that some simple public number is enough to authorise payment.