Homestyx hydra

R1:026ec11b9d6b

Add a rate limit for guessing old passwords when changing passwords

Summary:
Depends on D18904. Ref T13043. If an attacker compromises a victim's session and bypasses their MFA, they can try to guess the user's current account password by making repeated requests to change it: if they guess the right "Old Password", they get a different error than if they don't.

I don't think this is really a very serious concern (the attacker already got a session and MFA, if configured, somehow; many installs don't use…
Repository: R1 hydra
Commit Date: Jan 23 2018