• Septimaeus@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    22 days ago

    Suggesting that an authorized user would re-attempt the correct login?

    I have only one real-world example of a site where I would do that, and it’s because I know that it behaves this way (though for that site, if I had to guess, it’s likely a bug related to poorly designed async handling rather than an explicit check like in the comic). In most cases, I would assume PW recorded incorrectly in the first place and go straight for the password reset workflow.

    Not sure how representative that user behavior is, but the population is N ≥ 1.