*) sure, it had to be applied properly😅
*) sure, it had to be applied properly😅
- from a threat modeling perspective the main issue here is a password reuse (i.e. something like credentials stuffing from an attacker perspective); you cannot fix it reliably at server side with passwords only2/3
- from a threat modeling perspective the main issue here is a password reuse (i.e. something like credentials stuffing from an attacker perspective); you cannot fix it reliably at server side with passwords only2/3
- I believe that security part has to complement the organization's goal (i.e. in this case to ease a new user registration process a clear error message is required; 1/3
- I believe that security part has to complement the organization's goal (i.e. in this case to ease a new user registration process a clear error message is required; 1/3