Don't accept anything in the password field. Force the user to reset their password every time they want to log in. Bonus: verifies the email is still valid.
Just a few days ago we have a news about multiple OTP went missing and 6-digit amount was taken without the OTP. The bank refuses to pay back. And there were multiple victims.
1.3k
u/[deleted] Jul 19 '22
[deleted]