Comment 9 for bug 1688137

Revision history for this message
Lance Bragstad (lbragstad) wrote : Re: Attacker may use PCI-DSS 8.1.6 and 8.1.7 to lock out users indefinitely

I think our first course action is to implement Morgan's suggestion, where user information is only emitted if the password is correct.