Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
nick__m
3y ago
0 comments
Save
Share
You would have to randomize the error when the wrong password is inputed and ensure that for a particular username the returned error is invariant. Else an attacker could infer that when you get a different error you have a correct password.
0 comments
1 comments · 1 top-level
top
newest
oldest
ezekg
3y ago
The bad password error would only be sent if the second factor is valid, though.
j
/
k
navigate · click thread line to collapse