<div dir="ltr">+1</div><div class="gmail_extra"><br><div class="gmail_quote">On 3 March 2016 at 13:10, Bruno Oliveira <span dir="ltr"><<a href="mailto:bruno@abstractj.org" target="_blank">bruno@abstractj.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Good morning, today I was thinking about our brute force flow and was wondering if we could change it.</div><div><br></div><div>I know it's not our job to be a firewall or IDS. At the same time, our current flow today make passwords guessable for attackers. A successful login attempt is clearly distinguishable based on the error response.</div><div><br></div><div>TL;DR if a password is invalid we get "Invalid username and password", but if it's valid we get "Account is temporarily disabled, contact admin or try again later.". Which pretty much means that an attacker could complete the attack from another machine or later, because now she knows that such account exists and it's valid.</div><div><br></div><div>What I would like to suggest, it's just to remove the error message for account disabled. This information is relevant for the Keycloak administrator, but I don't think it's necessary for the final user. People will contact the admin anyways.</div><div><br></div><div>Thoughts?</div></div>
<br>_______________________________________________<br>
keycloak-dev mailing list<br>
<a href="mailto:keycloak-dev@lists.jboss.org">keycloak-dev@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/keycloak-dev" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/keycloak-dev</a><br></blockquote></div><br></div>