2 ms·
I'm not sure if someone has mentioned this already, but if someone has gone down the path to allow enumeration (username check during signup, which is immediate
by mrmattyboy 4y ago
I'm not sure if someone has mentioned this already, but if someone has gone down the path to allow enumeration (username check during signup, which is immediately returned ton the user), I would say this is a strong argument where you could protect yourself against enumeration more easily..
The amount of times a user will likely type their username/password incorrectly is going to be a lot higher than those who attempt to re-signup for an account. Therefore adding additional protection to the signup page (hard rate limiting, bot-protection) then aids to stop this username/email enumeration without the need to be as strict on a login page. This is also compiled with ip-based rate limiting/bot protection that can get very frustrating for users within a corporation that have single public IPs for all their users.