Vanguard投资平台的密码重置功能存在设计漏洞。1用户使用1Password生成的超过20字符的密码在重置表单中被浏览器自动截断至20字符,1而登录页面的密码输入框并未设置相同的字符限制,1导致重置时设定的密码与登录时实际输入的密码不匹配,最终无法成功登录。1
问题的根源在于密码重置表单的密码输入框被设置了HTML的maxlength="20"属性限制。1这种做法被认为是不应将该属性用于密码字段的典型反面案例。1正确的做法应该是采用JavaScript或后端验证来控制密码长度,而非依赖HTML属性进行客户端限制。1
A user discovered a critical design defect in Vanguard's password reset system that prevents successful account access 1. The password input field on the reset form is constrained by an HTML maxlength="20" attribute, which automatically truncates passwords longer than 20 characters during the reset process 1. When the user attempted to set a password generated by 1Password—which exceeded 20 characters—the browser silently cut it short 1.
The problem compounds because the login page's password field contains no such length restriction 1. This mismatch means the truncated password stored during reset does not match what users enter when logging in, leaving them locked out of their accounts 1. Security experts note that the maxlength attribute should never be applied to password fields; instead, validation should occur through JavaScript or backend processes to prevent silent data loss 1.
评论
还没有评论,欢迎留下第一条。