Tl;Dr
Prove how you would find my username using the login form. You can't, targetted attacks aren't happening and untargetted attacks won't be happening either.
Calling this user enumeration isn't even accurate. You're implying that there is a sustained amount of bots going round spending significant resources into brute force searching an incredibly vast search space that is rate limited and unbounded, all to target random users with DOS attacks on a game where there's 275 million accounts and only 1 million unique active players per month. And they spend this vast amount of time and money, rather than on something such as cryptomining or running bot networks, simply ruining random peoples days, with no way of knowing if it is even successful because the chances are that any single account you might happen to find is inactive to begin with.
It doesn't make technical sense. It would take too long to brute force. It doesn't make financial sense, nobody is spending this much money to troll some radom kid they've never met. It doesn't make sense. There's literally no good reason to believe that OSRS showing 2FA without a password is an actual problem.
16-Nov-2020 02:18:37
- Last edited on
16-Nov-2020 03:19:55
by
Hmm