4 ms·
If you don't ask for email validation and you don't implement an API rate limiting many hackers can create a script that will fill your database with random gen
by raresp 9y ago
If you don't ask for email validation and you don't implement an API rate limiting many hackers can create a script that will fill your database with random generated users and you won't understand what happened.
This is a simple example that demonstrates why you should and must implement email verification.
More.. you should block the account when a user enters wrong password 5 times during a 2 minutes period for example (you can adjust these numbers). This is also a good security measurement.
Even more.. you shouldn't fake business numbers. Customers and investors will lose their trust in you.
- niko001 9y agoThat doesn't make sense. Even a non-verified user lives as a row in your database. Sure, you can delete them if they haven't verified their address after 24 hours, but that doesn't mitigate the problem of filling your database before that.
- raresp 9y agoAre you following the Silicon Valley TV series? In the first episode of the last season they use a botnet network to hack a pizza application, they create a lot of users and generate thousands of orders. They manage to put the pizza company in bankruptcy. That's just a TV show, but the example is so good.