Password lockout approach

Cantor, Scott cantor.2 at osu.edu
Fri Jun 24 17:22:07 EDT 2016


On 6/24/16, 5:15 PM, "dev on behalf of Eric Goodman" <dev-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:

>But the storage method would have to be server side and not associated with a session for
>this to be meaningful, right? Otherwise as an attacker, can't I zero out any client side
>storage/cookies and bypass the entire protection mechanism?

Yes, certainly. Like the replay cache, etc.

-- Scott

PS. Nice job dodging that MFA call this week. We all know the real reason. 8^))))





More information about the dev mailing list