Brute force protection

@memes

  • @kryptonianCodeMonkey
    link
    1302 months ago

    And label the text box “username” when it only accepts email address.

    • @helpImTrappedOnline
      link
      612 months ago

      Don’t forget to have hidden password requirements and secretly truncate any password longer than 12 characters.

      • @kautau
        link
        312 months ago

        Well yeah, if you don’t truncate the password to 12 chars how will you fit the plaintext in a memory efficient fixed latin1 CHAR column that only accepts letters, numbers, and underscores

        /s

        • @helpImTrappedOnline
          link
          12 months ago

          Intresting. At least they got their act together, even making a physical totp authenticator in the 2000s.

    • @[email protected]
      link
      fedilink
      English
      13
      edit-2
      2 months ago

      And then validate the email with a custom regex that definitely doesn’t account for all the valid syntax permutations defined by the several email-oriented RFCs

      • @[email protected]
        link
        fedilink
        32 months ago

        Only on mobile though, on desktop have different criteria. Perhaps give the text box an arbitrary max length of like 30 characters on sign-in but not on account creation.