Post
Topic
Board Service Announcements (Altcoins)
Re: Just-Dice.com : Play or Invest : 1% House Edge : Banter++
by
GOB
on 24/10/2013, 19:42:06 UTC

I could make it such that any time you log in using a "secret URL" link, the site pops up a warning message suggesting that you should set a username and password.

That should prevent the attack from working on people who read popup messages.  But that may be quite a small percentage of people.

Why even allow users to bypass creating a username and password (and 2FA)?