Ticket #630 (new task)

Opened 5 years ago

Last modified 3 years ago

Security audit of error messages displayed during login/registration

Reported by: BrianKoontz Owned by: unassigned
Priority: normal Milestone: blue-sky
Component: unspecified Version: 1.1.6.4
Severity: normal Keywords:
Cc:

Description

I have some reservations from a security standpoint about generating error messages that indicate a username does or does not exist (see #622). Someone could use this information to identify accounts to attempt password cracks on. At some point in the future, it might be prudent to revisit this mod and come up with something more secure (for instance, throttling to prevent multiple login/registration requests within a given period of time).

Related tickets: #622

Change History

Changed 5 years ago by NilsLindenberg

  • milestone changed from 1.1.7 to 1.1.7.2

Changed 3 years ago by BrianKoontz

  • milestone changed from 1.3 to blue-sky
Note: See TracTickets for help on using tickets.