> Steam accepted blank recovery codes for password resets
Sample buggy code (that I just made up):
(user_token is user supplied token, token is the correct token)
for(i = 0; i < strlen(user_token); i++) {
if(user_token[i] != token[i]) return false;
}
return true;
If code is blank this will falsely return true. This is also subject to truncation attacks.I'm trying to think of a bug where blank fails, but truncated versions do not.