this post was submitted on 13 Mar 2024
1018 points (96.9% liked)

Memes

45619 readers
482 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 

Brute force protection

@memes

(page 2) 50 comments
sorted by: hot top controversial new old
[–] [email protected] 34 points 8 months ago

The one guy got grey hairs in-between slides lol

[–] [email protected] 29 points 8 months ago (5 children)

If they had the password right the first try, that isn't a brute force attack, thats a credential leak.

[–] [email protected] 19 points 8 months ago

I think the author attempted first time login to be with the right password.

load more comments (3 replies)
[–] [email protected] 2 points 8 months ago* (last edited 8 months ago) (1 children)
load more comments (1 replies)
[–] [email protected] 28 points 8 months ago

This is negging for auth.

[–] [email protected] 78 points 8 months ago* (last edited 8 months ago) (1 children)

Well, I sometimes input the same password 15-times in a row, and it works only on the last try. ¯⁠\⁠_⁠(⁠ツ⁠)⁠_⁠/⁠¯

load more comments (1 replies)
[–] [email protected] 15 points 8 months ago* (last edited 8 months ago) (1 children)

Won't protect against an offline attack (just will confuse the hell out of the hacker) but might confound an online attack? Until someone gets wise and runs the tool a second time. Loving the chaotic neutral vibes here.

[–] [email protected] 4 points 8 months ago (1 children)

It doesn't really even protect against online attacks though. Like, if you're going through a list of known accounts, by definition it won't be any of those accounts' first time logging in, right?

And if you're not going through a list of known accounts, good luck getting anywhere with your attack any time this millennia

[–] [email protected] 15 points 8 months ago (2 children)

This would be per session, not lifetime.

[–] [email protected] 2 points 8 months ago

This makes it even more cursed

[–] [email protected] 0 points 8 months ago

Function naming could use some work then, it's not obvious that isFirstLoginAttempt would be session-aware.

Sorry, I'll stop being pedantic now

[–] [email protected] 8 points 8 months ago

This is a really interesting idea, but a password manager would throw a wrench in it.

I'd assume my password was invalidated or stored incorrectly, so I'd reset, then I'd try to log in, wtf... this website blows.

[–] [email protected] 24 points 8 months ago (2 children)

That's actually pretty smart

[–] [email protected] 8 points 8 months ago (1 children)
[–] [email protected] 1 points 8 months ago (3 children)
load more comments (3 replies)
[–] [email protected] 3 points 8 months ago

@kandoh
Yes haha. This way we can get back to the times where 4 characters passwords were sufficient 😃

load more comments
view more: ‹ prev next ›