You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently it is possible to find valid user accounts by bruteforcing /auth/forgotpw.
I understand the convenience of being always told what the problem is (from the user perspective), but at least some of use (or mabye even the most of us) use mokey to provide a self-service portal to an unsecure network or even expose it to the internet, which is why we should at least make this configurable.
Would be happy to get some more thoughts and opinions on this.
Cheers
- xx4h
The text was updated successfully, but these errors were encountered:
Agreed. This should probably always return success (from the user perspective) and just do nothing on the backend if and invalid user account was provided. Having this configurable would be nice. We do have some rudimentary rate limiting in mokey as well which makes brute forcing forgotpw slightly more challenging. If enabled, by default it only allows 15 POST requests per hour.
Currently it is possible to find valid user accounts by bruteforcing
/auth/forgotpw
.I understand the convenience of being always told what the problem is (from the user perspective), but at least some of use (or mabye even the most of us) use mokey to provide a self-service portal to an unsecure network or even expose it to the internet, which is why we should at least make this configurable.
Would be happy to get some more thoughts and opinions on this.
Cheers
- xx4h
The text was updated successfully, but these errors were encountered: