Originally posted by SidFeyDesigns
View Post
Hi SidFeyDesigns
That is intentional and part of PCI-dss requirement #6.5.5
https://www.pcidssguide.com/pci-dss-requirement-6/
“A common example of improper error handling is user ID and password input. If an attacker receives the message, "incorrect password provided," that error message is telling them they've given a correct user ID. Now, they can focus on hacking the password. The PCI DSS recommends using generic language in your error messages so that no useful information is accidentally given to attackers. Instead of saying "Incorrect password provided," try giving the error message, "Data could not be verified."
Hope this helps
-Eric
Leave a comment: