Brute force protection

@memes

  • @kryptonianCodeMonkey
    link
    1309 months ago

    And label the text box “username” when it only accepts email address.

    • @helpImTrappedOnline
      link
      619 months ago

      Don’t forget to have hidden password requirements and secretly truncate any password longer than 12 characters.

      • @kautau
        link
        319 months ago

        Well yeah, if you don’t truncate the password to 12 chars how will you fit the plaintext in a memory efficient fixed latin1 CHAR column that only accepts letters, numbers, and underscores

        /s

        • @helpImTrappedOnline
          link
          19 months ago

          Intresting. At least they got their act together, even making a physical totp authenticator in the 2000s.

    • @[email protected]
      link
      fedilink
      English
      13
      edit-2
      9 months ago

      And then validate the email with a custom regex that definitely doesn’t account for all the valid syntax permutations defined by the several email-oriented RFCs

      • @[email protected]
        cake
        link
        fedilink
        39 months ago

        Only on mobile though, on desktop have different criteria. Perhaps give the text box an arbitrary max length of like 30 characters on sign-in but not on account creation.