Provide an analysis as to how Disney could have protected itself from this attack.
Disney did not use some of the best practices that can protect users. There’s no two-factor authentication—that’s a no-brainer. And Disney should obfuscate the existence of an account, not validating one way or the other whether an account exists.
Comments
Leave a comment