• rizzothesmall@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    8 days ago

    Being able to determine if a username is valid without a valid password is a security flaw

    Even something as simple as taking longer to validate the password when the username is a valid one can also lead to user enumeration

      • marius@feddit.org
        link
        fedilink
        arrow-up
        0
        ·
        7 days ago

        There are also a lot of websites where you first just enter a username and only when that is valid they ask for a password

        • psud@aussie.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 days ago

          Many of those will progress to password even if the user doesn’t exist