Comment 1 for bug 1203924

Revision history for this message
Aaron Wells (u-aaronw) wrote : Re: Bruteforce user enumeration vuln in password reset screen

I'm considering this one a relatively low priority because:

1. It's bruteforce user enumeration, which means you already have to have some idea of which ones are present.
2. There's already a much more direct user enumeration attack available in Mahara: https://bugs.launchpad.net/mahara/+bug/1158625
3. Because Mahara is a social network, usernames are not particularly secret to begin with.