4 ms·
> However, although there are nearly a billion possible auto-generated urls for the download link and they generally only last a short time Not enough. One lea
by highCs 10y ago
> However, although there are nearly a billion possible auto-generated urls for the download link and they generally only last a short time
Not enough. One leak can potentially ruin your reputation. So now, I fire dozens of thousand requests per minute and over a couple of hours I'll get something -- assuming there is dozens thousand of files at any given moment.
- a12k 10y agoHow many would you recommend for better security? The thought was that these links wouldn't last long, and the files are deleted upon expiration. But of course trusting obscurity for security is a flawed concept in itself. But looking for a good middle ground.
- throw309490 10y agoreCAPTCHA and throttling after suspicious number of failed attempts by an IP. Four digit PIN prompt that gets displayed even when requesting invalid URL. Make PIN verification backend request include some nonce associated with original request, and force nonce to be regenerated if PIN verification fails. PIN is also as easy to communicate verbally as URL.