Brute force protection

@memes

    • @[email protected]
      link
      fedilink
      642 months ago

      Don’t forget to have hidden password requirements and secretly truncate any password longer than 12 characters.

      • @[email protected]
        link
        fedilink
        342 months ago

        Well yeah, if you don’t truncate the password to 12 chars how will you fit the plaintext in a memory efficient fixed latin1 CHAR column that only accepts letters, numbers, and underscores

        /s

        • @[email protected]
          link
          fedilink
          12 months ago

          Intresting. At least they got their act together, even making a physical totp authenticator in the 2000s.

    • @[email protected]
      link
      fedilink
      English
      13
      edit-2
      2 months ago

      And then validate the email with a custom regex that definitely doesn’t account for all the valid syntax permutations defined by the several email-oriented RFCs

      • @[email protected]
        link
        fedilink
        32 months ago

        Only on mobile though, on desktop have different criteria. Perhaps give the text box an arbitrary max length of like 30 characters on sign-in but not on account creation.