4 ms·
How many would you recommend for better security? The thought was that these links wouldn't last long, and the files are deleted upon expiration. But of course
by a12k 10y ago
How many would you recommend for better security? The thought was that these links wouldn't last long, and the files are deleted upon expiration. But of course trusting obscurity for security is a flawed concept in itself. But looking for a good middle ground.
- throw309490 10y agoreCAPTCHA and throttling after suspicious number of failed attempts by an IP. Four digit PIN prompt that gets displayed even when requesting invalid URL. Make PIN verification backend request include some nonce associated with original request, and force nonce to be regenerated if PIN verification fails. PIN is also as easy to communicate verbally as URL.