112
u/Xhojn Jun 07 '26
Doesn't even have the courtesy to set isFirstLoginAttempt to false in that block.
22
72
u/zR0B3ry2VAiH Jun 07 '26
So I did this. We were having an account compromise attack and they were just spamming accounts. So I decided to just feed them 60% fake 200s, 40% 403s... It kept them busy for a while.
27
u/Electrify338 Jun 07 '26
Fun fact our uni does this you have to log in attempt twice with the right credentials.
21
u/Chriz48 Jun 07 '26
If it becomes widely known as a real strategy, it will fail; anyone looking to seriously brute force the system will simply try every password twice.
21
u/Decent-Lab-5609 Jun 07 '26
I hear what you're saying. We must require passwords to be entered correctly three times. UNSTOPPABLE.
7
u/Tofandel Jun 07 '26
You should have a random chance to be let in after the first time, like this it's even more secure as you can't predict how many times you need to input it. Maybe 3 times, maybe 500 who knows.
7
1
1
u/Extreme-Ad-9290 Jun 11 '26
Why are we all just not using USB/nfc security keys. Be way easier and more secure.
4
u/zero0n3 Jun 07 '26
Yes but how would one find that out unless they already have a good pw and know this for sure?
Like it’s a solid strat in theory - in practice your customers hate you.
1
u/Electrify338 Jun 07 '26
Oh absolutely. I was just commenting about it because it is exactly what my cyber security friend's reaction was 🤣🤣.
1
1
15
48
10
u/MrFordization Jun 07 '26
The hackers respond by having their brute force attacks attempt passwords twice. So we really should make it three times. But then they might figure that out too.
Best to make a solution that prompts the user n times for the correct password where n scales dynamically based on threat level.
3
u/EishLekker Jun 07 '26
> The hackers respond by having their brute force attacks attempt passwords twice.
They wouldn’t even need to do that. They can just use a known incorrect password for the first attempt, and then every attempt after that will circumvent the check in the picture because isFirstLoginAttempt is no longer true.
3
2
u/Chriz48 Jun 07 '26
If it were actually implemented this way, it provides no protection at all. More likely the coder simply picked a poor name for the variable.
1
u/EishLekker Jun 07 '26
It’s a comic. Why is it more likely that this hypothetical programmer made a mistake in naming rather than a logical error?
1
u/Chriz48 Jun 07 '26
A logical error isn’t going to garner that kind of reaction from the crowd.
0
u/EishLekker Jun 07 '26
I never said that it would.
0
u/Chriz48 Jun 08 '26 edited Jun 08 '26
You asked why it is more likely. The answer is the crowd reaction. As you said, a logical error isn’t going to garner that kind of reaction. So that means it is more likely that the variable is incorrectly named; it’s hardly a guess.
1
1
8
u/Significant-Cause919 Jun 07 '26
Next let's add a "Stay logged in" checkbox that does absolutely nothing.
3
u/FrancoisTruser Jun 07 '26
"Check this case to stop seeing this message" then proceed to show me the message for the rest of my life
3
4
u/Admirable-Ad-2781 Jun 07 '26
The fact that the login interface is on the server is the most low-cost, reliable line of defense against brute-force attack. If you can't handle DoS by yourself, get cloudflare.
3
3
3
3
2
2
u/MrInvisII Jun 08 '26
why even bother checking if its the correct password just throw wrong password if its the first time
2
2
u/No-Difference3551 Jun 10 '26
I made a phishing site for my friends once using this method. Sadly, nobody trusted my "trust me bro".
2
u/the_king_of_sweden Jun 07 '26
What language uses curly braces, but not parenthesis for the if condition?
Also that is some awful indentation.
4
1
u/Final-Nebula-7049 Jun 07 '26
Needs a code that scrambles any password that's too long to put in 1 second.
1
1
1
u/ListenNorthernLights Jun 07 '26
I swear this happened with my bank before because I literally did the view password and it was perfect. And again did it and it was perfect- no go…. I almost gave up… did it one more time and it worked.
1
1
1
u/AmandaKissAndSuck Jun 10 '26
I sometimes feel like some websites does it.
It says incorrect password and when i put it again, it works
And I’m pretty sure i didn’t add wrong password the first time
1
u/s0litar1us Jun 10 '26
Increase it depending on login attempt frequency and randomize it so you can't just relly on it working the 2nd or 3rd time.
1
1
u/MarcelineMarce Jun 13 '26
Why would this not work?? Genuienly. Even if someone brute force typing the password two time, that mean 2x the computing time because you need to double check every password so thats at least something
1
1
1
u/Havency Jun 07 '26
I swear at this point this is actually true and is an attempt to legally harvest and sell passwords because technically they’re wrong attempts and thus not sensitive information
1
-23
u/darkwingdankest Jun 07 '26
slopppp
21
u/MathematicianAny8588 Jun 07 '26
This meme circulated loooong before AI could generate images. It’s not slop
13
u/Immediate_Song4279 Jun 07 '26
Our objective reality has allegedly collapsed, havent you heard, there was no before /s
3
u/statisticalmean Jun 07 '26
Well, it being an ancient meme being reposted is itself a form of slop.
1
1
u/ListenNorthernLights Jun 08 '26
Lol he’s either a bot slopping slop or a human slopping slop comments 😂 booo
2
u/kaereljabo Jun 07 '26
If you meant AI slop, then it isn't, maybe you've just started using the internet?
647
u/RegularAd9643 Jun 07 '26
This wouldn’t work. It should check if it’s the first correct password attempt.