authentication 您所在的位置:网站首页 password are incorrect authentication

authentication

2023-09-30 04:20| 来源: 网络整理| 查看: 265

Although from a technical point of view the risk could be considered limited (as suggested by @Daisetsu) if the authentication mechanism is properly implemented, the system is still leaking data.

Going a bit deeper into whether this is a terrible risk or not. It depends on several things such as:

Is rate limiting in place? After X amount of failed attempts, are requests blocked (or is a captcha shown)? What is the password policy? Is multi factor authentication in place?

You basically have 50% of the credentials and a password guessing attack can be quite simple.

Now I am no General Data Protection Regulation (GDPR) expert but an email address in specific case can be considered personal data:

It depends whether or not a natural person is identified or identifiable based on the email address. The way persons have structured their email addresses has to be taken into account in order to determine whether the email address can be seen as personal data or not.

Source: https://lawandmore.nl/en/blog-nl-en/email-addresses-and-the-scope-of-the-gdpr/

In other words, it also depends in what country you reside and what laws are applicable when it comes to personal data.

Can you direct me to appropriate resources that elaborate on valid error messages to be shown or any protocol to be followed for such login scenarios.

In both cases (invalid email address and invalid password), the message should just display something like: "Username and/or password are incorrect."



【本文地址】

公司简介

联系我们

今日新闻

    推荐新闻

    专题文章
      CopyRight 2018-2019 实验室设备网 版权所有