Hide whether an account exists or not #12
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently,
/auth/login
indicates whether the tried username exists or not. To fix this privacy issue, the same message should be answered if the username doesn't exists and if the password is wrong. The answer should also be constant time to avoid timing attacks.