Re: [funsec] How *NOT* to handle incorrect passwords ...

2013-07-25 Thread Valdis . Kletnieks
On Thu, 25 Jul 2013 10:59:55 -0700, "Rob, grandpa of Ryan, Trevor, Devon & Hannah" said: > https://twitter.com/cjcheshire/status/360326695137468416/photo/1 > > Virgin Atlantic feels that it is a good idea to provide the failed password, > in plain > text, in the URL when you try for a reset ...

[funsec] Unintended consequences of anti-fraud algorithms

2013-07-25 Thread Rob, grandpa of Ryan, Trevor, Devon & Hannah
http://www.theverge.com/2013/7/24/4549124/how-google-uncovered-a-chinese- ring-of-car-thieves or http://is.gd/59l7XD Google's AdWords anti-fraud scanning finds theft of a different kind. == (quote inserted randomly by Pegasus Mailer) rsl...@vcn.bc.ca sl...@victoria.tc.c

[funsec] How *NOT* to handle incorrect passwords ...

2013-07-25 Thread Rob, grandpa of Ryan, Trevor, Devon & Hannah
https://twitter.com/cjcheshire/status/360326695137468416/photo/1 Virgin Atlantic feels that it is a good idea to provide the failed password, in plain text, in the URL when you try for a reset ... == (quote inserted randomly by Pegasus Mailer) rsl...@vcn.bc.ca sl...@vic