Risk mitigation of user name guessing is not done by obtuse error messages displayed back to the user. If you want to mitigate this risk, you need to use data.
Posts Tagged ‘security’
Login forms are broken in ruby on rails
Posted in software security, software usability, tagged don't do this, risk management, usability, security, ruby on rails on August 14, 2009 | 10 Comments »
Passwords gone wild
Posted in software security, tagged risk management, security on March 22, 2008 | 1 Comment »
Programmers are knuckleheads.