3 ms·
Background: I spent years developing a product that currently defends F500 websites against automated attacks. If you live in the US you've more than likely use
by brunoTbear 8y ago
Background: I spent years developing a product that currently defends F500 websites against automated attacks. If you live in the US you've more than likely used my software this week without knowing it.
Rate limiting is completely ineffective in preventing credential stuffing attacks from determined adversaries. The challenge is not brute-forcing, but credential leaks and password reuse. Attackers have access to vast seas of IP addresses and in my past life doing the defending, we would see an IP address involved in automation twice, and then it would go away forever.
- esotericn 8y agoI've covered this in a reply to another one of your comments, I think, so won't bother here.