diff options
author | Matthew Martin <phy1729@gmail.com> | 2014-06-26 12:36:51 -0500 |
---|---|---|
committer | Attila Molnar <attilamolnar@hush.com> | 2014-06-28 18:15:12 +0200 |
commit | 2cffabe0c7375a15c702aeaea5d553d90a549860 (patch) | |
tree | 4538d0f8b78ae73d6f9fd3f26dba9d1c4c3fd34d /src/modules/m_operlevels.cpp | |
parent | f78c1c277a80403d53c911893e6ae0a0d57f1cdc (diff) |
Check fingerprint before checking password (server linking)
Checking the password before the fingerprint means that even without the
correct cert it's possible to brute force the password or leak
information about it. Checking the fingerprint means attackers must
forge the cert before they can learn any information about the password.
Diffstat (limited to 'src/modules/m_operlevels.cpp')
0 files changed, 0 insertions, 0 deletions