Viking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-21 day agoThe inner fire of my hatred COULD melt steam beamslemmy.dbzer0.comimagemessage-square52linkfedilinkarrow-up1510arrow-down115file-text
arrow-up1495arrow-down1imageThe inner fire of my hatred COULD melt steam beamslemmy.dbzer0.comViking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-21 day agomessage-square52linkfedilinkfile-text
minus-squareJackbyDev@programming.devlinkfedilinkEnglisharrow-up14·1 day agoI think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
minus-squarebitchkat@lemmy.worldlinkfedilinkEnglisharrow-up6·1 day agoSame reason why you shoukd not validate username independently from password.
I think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
Same reason why you shoukd not validate username independently from password.