Enable configuration of credential pairs #3393
Labels
Complexity: Low
Feature
Issue that describes a new feature to be implemented.
Impact: Medium
sp/8
UI
User Interface
Milestone
Description
Brute-force exploiters prioritize credentials pairs over other combinations of credentials. That is, if a credentials collector steals a username/password combination, the exploiter will try this combination before combining the username with other passwords. The logic is that if the credentials were stolen as a pair, they're most likely to work as a pair.
The UI does not (currently) allow users to configure credentials as pairs. Rather, credentials are collections of different types of identities and secrets. Enable the user to specify identity/secret pairs in the UI. The option to specify just identities and secrets which will later be combined should be preserved
Tasks
Mockup
The text was updated successfully, but these errors were encountered: