2 ms·
This seems like a boon to credential stuffing attacks. Given a list of passwords and email addresses, having a well known, email keyed URL would allow an attack
by awkward 3y ago
This seems like a boon to credential stuffing attacks. Given a list of passwords and email addresses, having a well known, email keyed URL would allow an attacker to quickly find if any of the emails have an account on the service, before going through the better secured and more time consuming login page.