3 ms·
WAF, IP blacklists, naive bot detection[0] and why would a decent thresholding system allow for a single IP to fail multiple accounts in a short time period. I
by odammit 9y ago
WAF, IP blacklists, naive bot detection[0] and why would a decent thresholding system allow for a single IP to fail multiple accounts in a short time period.
If you hit two valid accounts [1] with bad passwords in a few ACCEPTABLE_UNIT_OF_TIME, it’s captcha time.
Thresholding isn’t just action per IP it’s being smart about how people are going to attack your system. It requires thought and upkeep.
[0] Previous thoughts on bot detection: https://news.ycombinator.com/item?id=16182405 https://news.ycombinator.com/item?id=16182405
[1] Also, if your login identifier and your public “display names” (usernames) are the same thing, that is a disservice to your users’ security.