Ugh and many people have made memes and such of this but its so annoying. If your policy says its to old then just have that in the message. Implying its the wrong one just pisses people off. You have a password manager and you know its the right one but you do the forgot password link and then when you put your password manager one in the truth comes out as it says you can’t use your current password. I swear non of the actual IT people from my heydey would ever do this. I feel like its the cs/mba types that bring all this bs.

  • HubertManne@piefed.socialOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    account locking is a mitigation for ddos. without it people still cannot log in because that is the nature of a ddos and with it the systems won’t put as much processing to the login request. Don’t get me wrong its not meant as mitigation of ddos as a purpose of using it but the example of how account locking is going to make user experience during a ddos is ludicrous.

    • BetterDev@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 month ago

      Are you deliberately trying to troll me?

      Look man, you either completely misunderstood (my bet) or purposefully misrepresented what notabot said, and all I did was come here in good faith and try and explain it to you. You have, for 3 days now, completely missed it, and pointed out that back-end enumeration mitigation isn’t the specific feature you’re complaining about.

      I never once said that it was.

      The only concept I’ve been trying to communicate to you, through my own frustration, is this:

      On a simple login endpoint, if there’s bits of information that differentiates one scenario from another, then you have provided a vulnerable surface that can be abused to extract information.

      It doesn’t matter how likely it is.

      It doesn’t matter how hard it is.

      It doesn’t matter if we’re talking about an embedded device, an api endpoint, or a database server.

      It doesn’t matter if that information is a response code, a failure message, or a response time.

      If youre responses are differentiable based on enumerating the possible inputs, that leaks data.

      I’m aware that has nothing to do with showing you a pretty little message. I just wanted to be a source of information for you.

      I have been patiently explaining the core of the above concept through simplified examples, and attempting to engage in a meaningful discussion where (hopefully) you walk away knowing something new.

      I never set out to lay out the grand design of a perfectly impregnable digital fortress, nor by contrast explain the nuances of every single technique in the hacker’s arsonal. I never suggested you were wrong that websites can securely tell you your password’s expired. I was explaining the idea behind notabot’s comments which you clearly didn’t understand.

      That’s not to say I agree fully with notabot, but they came here, and they tried to tell you about a concept they knew a bit about. That’s kind. Correct or not, they tried doing something nice for you.

      You mischaracterized what they were trying to say, so I tried to step in and fill in a few conceptual blanks for you. Next time I’ll just keep my mouth shut. I’m sorry I intruded into your safe space where you just wanted to feel vindicated in how you felt due to a bad user experience.

      Have a nice life.

      P.S. DDOS doesn’t mean what you think it does. Its broader than that. DOS = Denial of service. That can take many forms. One form would be overwhelming the infrastructure and causing the service to stop responding. That’s what you’re thinking of. Another form would be making it where all the users can’t log in. Same effect, the service isn’t being provided anymore. Nobody can log in. D = distributed, meaning you can’t just IP block the jerk who’s keeping your users locked out. And locked out doesn’t necessarily mean what you seem to think it does either. One form of lockout means “contact the admin so they can unlock your user”, another means I just keep failing to sign in as you, hundereds of times, and the service never lets the real you in, correct password or not. I hope you at least learned a few new words today.

      • HubertManne@piefed.socialOP
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        its all so disengenous when you take into account my original post. saying theortically this even if in actuality it does not mean much. I also think ddos does mean what I say because anyone who uses it generally means overwelming the system with traffic. your possible other type is almost never talked about. no article talks about a company being ddosed by making loging attempts with a list of users at just the pace necessarily to keep them locked out.

        • BetterDev@programming.dev
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Oh is there some rule that I can’t just respond to a comment thread? Every comment has to be about the original post?

          Wild. I had no idea. Can you point me to a source for that claim please? As evidenced by the thread, I love learning!

          Well, see, there’s people who talk about security, and there’s people who talk about security. Most people are the former.

          But hey, I asked you for a source, it’s only fair for me to reciprocate: oh no! You were wrong on the internet today!

          • HubertManne@piefed.socialOP
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            you can reply all you want but when its way off base youll get guff for it. I will use the term again but making out like I am citing some imaginary rule is disengenous and contrary to simple communication between individuals. Thats a really great source of page not found btw.

            • BetterDev@programming.dev
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              disengenous

              You keep using that word. I do not think it means what you think it means.

              I was being sarcastic, friend.

              And at this point I’m cool with you just being a troll.

              I’m a troll too sometimes, I get the thrill. Anyway, it’s been a fun few train rides writing this thread with you.

              Maybe I’ll see you around ;-)

              • HubertManne@piefed.socialOP
                link
                fedilink
                English
                arrow-up
                2
                ·
                1 month ago

                ok you were being sarcastic but that is hard to do on the internet. when you look at me like that it was a joke. fine. then there is nothing to say other than you where being sarcastic in a thread and didn’t really mean what you said. thing is it seemed like you were deflecting from your topic which is a common thing a person does who feels like they have to win at all costs so they throw in some unrelated thing and start arguing about that. im sorta glad actually you mentioned it as im looking for a genuine experience (and I certainly do know what the word means even when I misspell it) and I work to keep my feed that way.

                • BetterDev@programming.dev
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 month ago

                  On the sarcarm thing, yeah that’s true enough. I think I’m funny, but it’s impossible for me to predict how that’s going to come off to someone who doesn’t know me. And sorry if my line about the “disingenuous” thing didn’t land, it’s a Princess Bride reference, I just wanted to sneak it in there inconceivably.

                  Nice on the “genuine experience” thing. How’s that working out so far? I’ve had pretty good luck on Lemmy using programming.dev, but I’m usually more of a lurker than a contributor. The only reason I’ve been active lately is that I’ve started commuting so I’ve got some downtime when I can’t do much else.

                  I definitely know what you mean about double-down behavior. I come across it all the time and usually just let it ride. “Not my job” to teach internet strangers stuff lol. I’ve also been in relationships with people who act that way all the time, on every topic, and eventually it becomes clear that what they’re after isn’t consensus, its’s persuasion, so if I don’t budge they feel like they’re losing some kind of battle. I’ve mostly learned to avoid those sorts. If you want to learn to spot it in the wild, I think the term is DARVO.

                  I am just one of those people who reads wikipedia for fun, watches educational content primarily, and has a million hobbies, so I know a little about a lot of topics. I really want to share that knowledge with people but have a hard time doing so, I think I come off as pretentious, but genuinely don’t judge people or rank them into better or worse.

                  People are just people to me. Sometimes people do bad things, some people do bad stuff all the time, but I know that somehow, in their mind, they think they’re right in doing so.

                  Anyway, I did feel a little spicy last night when I wrote my last few replies, so it makes sense that you read me as being hostile and disingenuous. I wasn’t trying to be, but I know I can come off as pretty abrasive when I’m frustrated.

                  • HubertManne@piefed.socialOP
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    1 month ago

                    I feel one of the good things with the fediverse is you have a lot of control. I generally champion for as much user control as possible and I saw a lot of it in kbin and when it fell piefed sorta took up the gauntlet. I peruse all and block communities I have no interest in because I want to see new communities I might have interest in which does not work if you subscribe. Piefed tried to solve it with topics but I find all and blocking the way to go. When it comes to users I ususally due dilegence before blocking. Before looking through history to see if its common behavior or if they are just having a bad day. Also if they seem to be real and varied. Like people who only post in one particular way im more likely to as I either think they are bots or just obsessed with one type of thing. Piefed has this great thing now where you can make personal notes on users so its easier to not jump the gun. There are definately some very interesting folk and even things like this are nice as its good to be challenged. Not as much on something with get off my chest which is a community for bitching about something that bugs you but I like places were I can learn something. Ill admit though I have a chip on my shoulder with security in tech from my own IT experiences.

              • HubertManne@piefed.socialOP
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 month ago

                Thanks. I will point out there is no severity rating or example of it being used in the wild. I don’t recall ever seeing a news article on how some company is ailing do to an attack like this. Then after all that I doubt anyone. ever. would think the way to fix it wold be not not have lockouts. which are pretty much a mandatory security item at this point. temporarily for mitigation. sure. in general not having it. you would have to be crazy.