4 ms·
Any advice on where to read more about these modern cred stuffing countermeasures? I'd love to learn more.
by bigblind 8y ago
Any advice on where to read more about these modern cred stuffing countermeasures? I'd love to learn more.
- brunoTbear 8y agoA relatively successful company in the area is Shape Security. Their marketing is a bit painful, but they invented the concept of cred stuffing. Disclaimer: I worked there for four years.
- bsamuels 8y agoUnfortunately I don't have much reading material to provide. It's a bit of an arms war, so the latest and greatest countermeasures are typically kept secret/protected by NDA. The rabbit hole can go very deep and can differ from company to company. The most drastic example I can think of was an unverified rumor that a certain company would "fake" log users in when presented with valid credentials from a client they considered suspicious. They would then monitor what the client did - from the client's point of view it successfully logged in and would begin normal operation. If server observed the device was acting "correctly" with the fake login token, they would fully log it in. If the client deviated from expected behavior, it would present false data to the client & ban the client based on a bunch of fancy fingerprinting. Every once in awhile, someone will publish their methods/software; Salesforce and their SSL fingerprinting software comes to mind: https://github.com/salesforce/ja3 https://github.com/salesforce/ja3
- brunoTbear 8y agoThis is a rare paper published on the topic. https://link.springer.com/chapter/10.1007%2F978-3-319-07536-5_30 https://link.springer.com/chapter/10.1007%2F978-3-319-07536-...
- sjwright 8y agoFundamentally it's a question of fingerprinting the behaviours of humans versus bots. The problem is that it's becoming increasingly difficult to distinguish them, particularly when bots are running headless chrome or similar, and real users are automating their sign-ins with password managers. I don't do much of this sort of thing, but numerous things come to mind. Aim to identify and whitelist obviously human browsers, blacklist obviously robot browsers, and mildly inconvenience/challenge the rest. For example, an obvious property of a real human browser is that it had been used to log in successfully in the past. Proving that is left as an exercise for the reader, though it inevitably requires some state/memory on the server side.
- zby 8y agoA company I am considering investing into: https://fingerprints.digital/ https://fingerprints.digital/
- aembleton 8y agoAre they looking for funding? They appear to be privately funded.
- zby 8y agoThey have been at https://www.wolvessummit.com/ https://www.wolvessummit.com/ - they are preparing for a funding round. You can find them at other events listed on their page: https://fingerprints.digital/event/ https://fingerprints.digital/event/