×

Good News Everybody!

The new search engine is LIVE!

Please report any problems to david (at) midrange.com.




>snip
A bigger 'vulnerability' in the same vein is that the sign-on screen is
quite happy to tell you too much information - it will tell you if the user
profile  does/doesn't exist (half the battle) and then it will tell you,
once you have a valid user profile, whether you got the password
right/wrong.
>end snip

Can't you change the message to say that?

Mike


This thread ...


Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.