468
top 50 comments
sorted by: hot top new old
[-] eager_eagle@lemmy.world 154 points 5 months ago
[-] AlbertUnruh@feddit.org 70 points 5 months ago
[-] eager_eagle@lemmy.world 29 points 5 months ago* (last edited 5 months ago)

whew

thankfully they redacted the phone nunber

load more comments (1 replies)
[-] rizzothesmall@sh.itjust.works 138 points 5 months ago* (last edited 5 months ago)

Being able to determine if a username is valid without a valid password is a security flaw

Even something as simple as taking longer to validate the password when the username is a valid one can also lead to user enumeration

[-] cactusupyourbutt@lemmy.world 17 points 5 months ago

I keep hearing that, yet the websites will gladly tell you that the username is taken when trying to register

[-] meekah@discuss.tchncs.de 6 points 5 months ago

I'd assume the spam protection for signing up is a lot tighter than the one for logging in

load more comments (5 replies)
[-] theo@lemmy.world 14 points 5 months ago

I was having a chat about this with a UX guy. His argument for using a similar flow was that the username/email will have to be validated at the point of registration anyway so you might as well make it easier for the user when the email is wrong. I couldn't really refute this logic.

If you throttle both login and registration, then surely the risk is minimised while keeping the user happy?

[-] LeapSecond@lemmy.zip 21 points 5 months ago

You see the registration problem in so many places. If the username is an email, the proper way to validate it without revealing if an account exists is to accept any email address and if it already exists say that in the registration email you would send anyway. With the appropriate throttling if needed.

load more comments (4 replies)
load more comments (1 replies)
[-] the_riviera_kid@lemmy.world 110 points 5 months ago
[-] kryptonianCodeMonkey@lemmy.world 56 points 5 months ago

"Wrong username. Correct password."

"Uh.... who's password?"

[-] bleistift2@sopuli.xyz 22 points 5 months ago* (last edited 5 months ago)

I don’t know who is password, or why is password, or when is password, but I do know where is password, and it’s out there!

[-] Buddahriffic@lemmy.world 6 points 5 months ago

But... how is password? Secure enough?

[-] Buddahriffic@lemmy.world 16 points 5 months ago

Error: password already in use by CobainKiller94

load more comments (15 replies)
[-] roofuskit@lemmy.world 92 points 5 months ago

Just good security, nothing to see here.

[-] waigl@lemmy.world 63 points 5 months ago

Any further "helpful" information in that error message would be a security issue.

[-] gibson@sopuli.xyz 5 points 5 months ago

While true most of these websites expose valid usernames in other places

[-] mech@feddit.org 47 points 5 months ago* (last edited 5 months ago)

Yeah, the error message could be more helpful:

Wrong password. Try again.
Hint: the correct password is gHI6shTI2!

[-] kubica@fedia.io 12 points 5 months ago

2nd hint: Maybe your have a second account with any of this names: ...

[-] onlinepersona@programming.dev 9 points 5 months ago

3rd hint: their passwords are...

load more comments (2 replies)
[-] joyjoy@lemmy.zip 6 points 5 months ago

AI slop is great, isn't it?

[-] Pika@sh.itjust.works 6 points 5 months ago

Not gonna lie back when websites had password hints that you could do. I used to put something like that where it wouldn't be the full password, but it would be either a part of the password or I would label it as same as computer password or something like that.

God, I was so insecure when I was young.

[-] M137@lemmy.world 33 points 5 months ago

It's hilarious how all OP did with this post is show everyone how dumb they are.
Seriously, how do you NOT understand the security risk of that?

[-] lobut@lemmy.ca 14 points 5 months ago

I remember there was a joke about this back in the day were someone put a joke error message saying: "that password belongs to ninja123, please enter your password"

load more comments (2 replies)
[-] saltesc@lemmy.world 22 points 5 months ago* (last edited 5 months ago)

try all passowrds. Fail

Maybe I don't have an account...

create new account. email already in use. Fail.

Okay, guess I'll reset the password through email.

password can't be one already used. Fail

WHAT?!

[-] wheezy@lemmy.ml 8 points 5 months ago

I too only type my password correctly when I go to reset it.

load more comments (1 replies)
[-] TheFogan@programming.dev 12 points 5 months ago

yeah real question how would the website even know. Whole point is to match the 2 things together. Is hunter2 my password, well that depends who are you, we've got plenty of users that have that hunter2 password

[-] GamingChairModel@lemmy.world 12 points 5 months ago

The website could know whether the username actually exists on the system. But revealing that information is a security weakness because someone could at least learn who has an account at that site (especially if usernames are email addresses, as they often are).

[-] TheFogan@programming.dev 5 points 5 months ago

Right but not only is it a security weakness, but it's also not helpful to the user. Point is the username probably exists in the system.

Say I went to a website to register TheFogan, but TheFogan already exists, so I created TheFogan2.

3 years later I go back to the website, try and log in with username: "TheFogan" password: "Hunter2", and it tells me "your username is right but your password is wrong". But in reality I have the right password for my account, but the site would just think I have the wrong password for the guy who beat me to my account.

So yeah agreed the primary reason for it is security, IE a fully user focused, while having bad security practices would be, a "if the username exists in the system, report "Username and password don't match", if the username doesn't exist report "There is no user by this name in the system". My point is the site only can know if they have a user by that username, not whether that is MY username.

[-] TheYojimbo@lemmy.world 5 points 5 months ago

Not exactly. It should check for the username and password separately. First check if the user exists, then check if the salted passwords match.

[-] Pika@sh.itjust.works 3 points 5 months ago* (last edited 5 months ago)

Generally speaking, unless you're using OAuth for an authentication, you would check your username and your password at the same time. It's just you wouldn't respond if either existed or not. You would just say invalid username and password combination.

What gets really complicated is the hybrid SSO integrations where they use a username and then if the account has SSO enabled it then redirects you to the sign-in page, Otherwise, it brings you to a password field.

Realistically what these sites should do to prevent that vulnerability would be to make it so you have to click a dedicated sign in with single sign on button. But not everyone does that type of flow.

Granted, this also doesn't include sites that convert your user account into a user ID. And then for your password's table, only give a user ID. Those would require two queries or a join, regardless, because it's two separate data places. One to get the user Id and one to get the passwords

load more comments (1 replies)
load more comments (3 replies)
[-] RogueBanana@piefed.zip 11 points 5 months ago

Cisco VDI took their security to another level. Wrong password? system down? account locked? Always "Please try again later or contact support".

[-] RamenJunkie@midwest.social 11 points 5 months ago

My bigger beef is when I enter the wrong email and it rolls me over to a sign up screen.

Fucker, I have an account, I just don't remeber which of my 20 email addresses it is.

[-] zxqwas@lemmy.world 10 points 5 months ago

If they told you the user name is wrong you may as well publish a list of usernames of your site.

[-] MimicJar@lemmy.world 7 points 5 months ago

Website: Wrong user name or password.

Me: Password.

Website: Correct! Come right in.

[-] chattre@lemmy.blahaj.zone 6 points 5 months ago

"Something went wrong."

motherfucker I will OPEN UP THE NETWORK INSPECT TAB AND FIGURE OUT WHAT WENT WRONG.

[-] LeapSecond@lemmy.zip 15 points 5 months ago

Network tab: server returned an html page with the words "Something went wrong."

[-] Jakylla@jlai.lu 12 points 5 months ago
[-] 123@programming.dev 4 points 5 months ago

Had manager that wanted us to return error codes on a field of an API response along with an HTTP 200 because "errors bad". It needed a few of us to make him understand how that worked against common design patterns and you still had to handle error codes since you didn't know if the error would be coming from the app, web server, api gateway, local network (no internet), etc.

load more comments (1 replies)
load more comments (1 replies)
[-] mitsosimo@programming.dev 6 points 5 months ago

The absence of details makes the website more secure.

load more comments
view more: next ›
this post was submitted on 10 Apr 2026
468 points (90.8% liked)

Programmer Humor

33397 readers
490 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 3 years ago
MODERATORS