Replying to Avatar 0xtr

Okta, a huge company in the auth as a service world, had a nasty bug where people with usernames longer than 52 characters could log in without providing the password (as long as there was a previously cached successful login).

https://cybernews.com/security/okta-authentication-vulnerability/

Avatar
/dev/fd0 1y ago

I haven't seen anyone using 52 characters long username.

Reply to this note

Please Login to reply.

Discussion

Avatar
0xtr 1y ago

My usernames going forward will be two concatenated UUIDs

Thread collapsed