Viking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-215 days agoThe inner fire of my hatred COULD melt steam beamsimagemessage-square52linkfedilinkarrow-up1519arrow-down115file-text
arrow-up1504arrow-down1imageThe inner fire of my hatred COULD melt steam beamsViking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-215 days agomessage-square52linkfedilinkfile-text
minus-squareJackbyDev@programming.devlinkfedilinkEnglisharrow-up16·15 days agoI think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
minus-squarebitchkat@lemmy.worldlinkfedilinkEnglisharrow-up6·15 days agoSame reason why you shoukd not validate username independently from password.
I think what happens is that your password is expired but rather than telling you it says it is incorrect. This way it doesn’t leak what the current but expired password is.
Same reason why you shoukd not validate username independently from password.