• They keep multiple old passwords. You’ve done this whole stick before and you tried to use that same password last time. You use it for everything, and every time your new account gets “hacked.” You keep using that password even when we show you that it’s been in multiple leeks and is associated with your email.

    “But I like the password, it’s my favourite football team!”

  • Thorry ( Thorry@feddit.org ) 
    link
    fedilink
    arrow-up
    7
    ·
    1 year ago

    That’s because you’ve been rate limited trying passwords for an hour. When an attacker is randomly trying incorrect passwords, even the correct password will be rejected. Otherwise the protection wouldn’t be very useful.

    • kibiz0r ( kibiz0r@midwest.social ) 
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      Had a convo with someone a while back:

      Bug report: “The ‘reset password’ form doesn’t show an error if you try to reset an account that doesn’t exist.”

      Me: “That would be a security risk. Closed.”

      Them: “What? How? You have to click the link in the email before it does anything.”

      Me: “Try putting in a bogus email on the login screen. See how it says ‘wrong email/password combination’, and not ‘no such account’? If we tell the user whether we recognize a given email, we’re basically providing attackers a list of users they can try passwords for.”

  • \[DUMBASS]/ ( dumbass@aussie.zone ) 
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 year ago

    There’s few things more violently infuriating than being told that… You fucking told me it was the wrong password in the first place for fuck sake, I only have 3 fucking password variants I use, but noooo you need a brand new, never before used by any human ever, password. Fuck you web developers!

  • Rhaedas ( Rhaedas@fedia.io ) 
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    I’ve always thought that the best password security possible would be to always have the real password fail a few times. People who know their password will keep trying it, someone else will try a different one. It’s a variation of not giving an error that tells what failed.