Multiple choice technology security

You have been asked to design an auctioning website.Each bidder is provded a unique login and password.Three invalid login attempts would cause the id to be logged out and any active session to be terminated.Which of the following would you avoid to prevent business logic flaws ?

  1. Prevent bidders from seing the bid amount by another bidders

  2. Allow bidders to see the login ID of other bidders

  3. Prevent a bidder from bidding more than thrice

  4. Set a cut off amount on the bids to be raised

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Allowing bidders to see others' login IDs enables targeted account locking (denial of service) by submitting three incorrect logins for those IDs, exploiting the lockout mechanism.