Password lockout approach

Eric Goodman Eric.Goodman at ucop.edu
Fri Jun 24 17:15:00 EDT 2016


>My only real constraint is that it has to use the storage API to be considered for inclusion.

But the storage method would have to be server side and not associated with a session for this to be meaningful, right? Otherwise as an attacker, can't I zero out any client side storage/cookies and bypass the entire protection mechanism?

--- Eric


More information about the dev mailing list