Viking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-221 days agoThe inner fire of my hatred COULD melt steam beamslemmy.dbzer0.comimagemessage-square52fedilinkarrow-up1521file-text
arrow-up1521imageThe inner fire of my hatred COULD melt steam beamslemmy.dbzer0.comViking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-221 days agomessage-square52fedilinkfile-text
minus-squareJackbyDev@programming.devlinkfedilinkEnglisharrow-up16·21 days agoI think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
minus-squarebitchkat@lemmy.worldlinkfedilinkEnglisharrow-up6·21 days agoSame reason why you shoukd not validate username independently from password.
I think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
Same reason why you shoukd not validate username independently from password.