• Agent641@lemmy.world
    link
    fedilink
    arrow-up
    11
    arrow-down
    1
    ·
    10 days ago

    This form can be used to brute force or dictionary guess passwords and infer what they are without a limitation on login attempts. Even if the password has already been invalidated on that service, finding a collision on this service gives you a password that might work on other services for the same email address/username

    • Clent@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 days ago

      And waiting for a form submit changes that in what way that cannot also be done on a debounce?