View Issue Details

IDProjectCategoryView StatusLast Update
0009645Talerlibeufin-bankpublic2025-03-20 21:12
ReporterAntoine A Assigned ToAntoine A  
Status assignedResolutionopen 
Target Version1.1 
Summary0009645: Lock account on password auth failure
DescriptionWe can't lock an account if password authentication fails, because the client username is public and guessable, which would allow anyone to lock any account, constituting a denial-of-service attack.
We have therefore chosen to lock the account if 2FA authentication fails, meaning that only accounts with 2FA are protected.
We could use a separate login ID, as some banks do. This ID would be randomly generated and can be rotated when leaked or attacked.
TagsNo tags attached.


There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-03-20 21:12 Antoine A New Issue
2025-03-20 21:12 Antoine A Status new => assigned
2025-03-20 21:12 Antoine A Assigned To => Antoine A