3 ms·
> If you want to stop password spraying, protect your hashes. Again, it's not about your hashes, it's about the attacker having access to your users' credentia
by nextgens 9y ago
> If you want to stop password spraying, protect your hashes.
Again, it's not about your hashes, it's about the attacker having access to your users' credentials.
Users re-use credentials accross services and you have no control on how (in)securely they are stored there.
Blacklisting (I don't have an opinion on how big the blacklist should be) what is known to be widely used accross services sounds sensible... and there is definitely an argument to be made about blacklisting what is known to be widely available/effective for attackers.