You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It should be prevented, that an attacker could get knowledge of the correct password. Till now, the login process works (as far as I understand it) this way:
type in user name
switch to the password field and type it in,
press Enter [password will be checked] and if correct
the TOTP-field is shown.
type in the TOTP
press ENTER and if correct, the login worked
For me this is a security flaw. It is not necessary to inform the attacker, that he know's the correct password.
The only right way - in my eyes - should be: If the admin has added the TOTP app (and at least one user has it activated,) show the TOTP field below the password field on the login screen from the start. Password and TOTP are checked.
The text was updated successfully, but these errors were encountered:
It should be prevented, that an attacker could get knowledge of the correct password. Till now, the login process works (as far as I understand it) this way:
For me this is a security flaw. It is not necessary to inform the attacker, that he know's the correct password.
The only right way - in my eyes - should be: If the admin has added the TOTP app (and at least one user has it activated,) show the TOTP field below the password field on the login screen from the start. Password and TOTP are checked.
The text was updated successfully, but these errors were encountered: