3 ms·
Why is Ring allowing brute forcing? Individual cameras should be set to only allow logins at least a few seconds apart increasing up to several minutes and perh
by michaeloder 7y ago
Why is Ring allowing brute forcing? Individual cameras should be set to only allow logins at least a few seconds apart increasing up to several minutes and perhaps blocking IP addresses with excessive volume. If they're brute forcing Ring's servers an application firewall would catch and block this.
- pgoggijr 7y agoI don't think that the above comment means brute-forcing in the "try a million different passwords in a short time-period" sense, it's referring to finding a list of known password and email combinations and trying just those. I would expect that a few attempts wouldn't trip any brute-force alarms.
- g4k 7y agoEspecially if you use a few thousand proxies.
- SirYandi 7y agoNot actually brute forcing individual ring accounts. They are just using previously leaked combinations
- goles 7y agoThe term for this type of attack is credential stuffing. https://www.owasp.org/index.php/Credential_stuffing https://www.owasp.org/index.php/Credential_stuffing
- grimmfang 7y agoThis comment shouldn't be downvoted. This is the correct term.