In reply to
rizzothesmall
@rizzothesmall@sh.itjust.works
sh.itjust.works
rizzothesmall
@rizzothesmall@sh.itjust.works
sh.itjust.works
@rizzothesmall@sh.itjust.works
·
Apr 10, 2026
Being able to determine if a username is valid without a valid password is a security flaw
Even something as simple as taking longer to validate the password when the username is a valid one can also lead to user enumeration
View full thread on sh.itjust.works
132
10
0
Conversation (10)
Showing 0 of 10 cached locally.
Syncing comments from the remote thread. 10 more replies are still loading.
Loading comments...