Hacker News new | past | comments | ask | show | jobs | submit login

For about six months, the Fidelity mobile site gave false indications of incorrect username/password on purpose. No idea why they did this.



I can see that it could be effective against brute force attacks. A real user would assume they fat fingered their password and try it again, a brute force attack would miss the password and carry on forever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: