“Invalid Username or Password”: a useless security measure

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • secure-sw-dev-fundamentals

    Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)

  • Exactly, if you reveal that an account exists when you just type in an email address, then you have a privacy failure and probably a security failure.

    For example, the OpenSSF's secure software development fundamentals course <https://openssf.org/training/courses/> in its section on minimizing feedback <https://github.com/ossf/secure-sw-dev-fundamentals/blob/main...> says:

    * If a user tries to create an account using an email address, don't tell the user if an account with that email address already exists. Similarly, if a user tries to do a password reset using an email address, don't tell the user if there is no account with that email address. Providing that information would allow an attacker to determine if a specific email address is being used (or not) by some existing account.

    Now for the unpopular take: not everyone lives in the US. The GDPR requires protection of personally-identifying information, and in many cases that includes email addresses that identify individuals. There are exceptions, but it's typically better to keep email addresses private unless the user specifically authorizes it.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • What Happened to DuckDuckGo?

    2 projects | news.ycombinator.com | 23 May 2024
  • DuckDuckGo Down

    1 project | news.ycombinator.com | 22 May 2024
  • How to Turn Off AI Overview in Google and Set "Web" as Default

    1 project | news.ycombinator.com | 22 May 2024
  • Installing CPAN modules from git

    2 projects | dev.to | 21 May 2024
  • Is artificial consciousness achievable? Lessons from the human brain

    1 project | news.ycombinator.com | 19 May 2024