11 ms·
Trying to stop credential stuffing by blocking bots will not work, and can often severely impact people depending on assistive technologies. I think a better s
by kseifried 5y ago
Trying to stop credential stuffing by blocking bots will not work, and can often severely impact people depending on assistive technologies.
I think a better solution is to implement 2FA/MFA (even bad 2FA/MFA like SMS or email will block the mass attacks, for people worried about targeted attacks let them use a token or software token app) or SSO (e.g. sign in with Google/Microsoft/Facebook/Linkedin/Twitter who can generally do a better job securing accounts than some random website). SSO is also a lot less hassle in the long term that 2FA/MFA for most users (major note: public use computers, but that's a tough problem to solve security wise, no matter what).
Better account security is, well, better, regardless of the bot/credential stuffing/etc problem.