Clearing my cache and cookies today and upon re-logging noticed I entered an auth code that had just expired. Thought I would be errored but to my surprise it was accepted. Tested with a few more logins and found it would accept the -1 code up to the expiration of the current code.
This doubles the odds for a brute force attack and there doesn't seem to be any time delay between log in attempts.
This may already have been reported or be an accepted known risk, but I didn't want to trawl through 14 pages of staff justifying the obvious benefits of account security. to find out.
This doubles the odds for a brute force attack and there doesn't seem to be any time delay between log in attempts.
This may already have been reported or be an accepted known risk, but I didn't want to trawl through 14 pages of staff justifying the obvious benefits of account security. to find out.