Password lockout approach
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 24 17:22:07 EDT 2016
On 6/24/16, 5:15 PM, "dev on behalf of Eric Goodman" <dev-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:
>But the storage method would have to be server side and not associated with a session for
>this to be meaningful, right? Otherwise as an attacker, can't I zero out any client side
>storage/cookies and bypass the entire protection mechanism?
Yes, certainly. Like the replay cache, etc.
-- Scott
PS. Nice job dodging that MFA call this week. We all know the real reason. 8^))))
More information about the dev
mailing list