3 ms·
I have a question about brute-force password cracking or any method that involves rapidly testing a hundred or more possible passwords: What prevents someone f
by Slow_Hand 4y ago
I have a question about brute-force password cracking or any method that involves rapidly testing a hundred or more possible passwords:
What prevents someone from securing the system by putting a limit on the number of login attempts before the application requires a cool down time before it will allow additional attempts?
I can't be the first person to have thought of this, so would someone please explain why is this not a viable security strategy?
- phone8675309 4y agoThis is useful strategy in a "yes, and" capacity - take other action AND tarpit login attempts. In some situations, the requirement might be locking the ability of an account to log in after X failed attempts over Y amount of time - say, 3 failed attempts in 5 minutes. Then it's necessary for the user to contact support/the sysadmin to unlock their account.
- pwg 4y ago> What prevents someone from securing the system by putting a limit on the number of login attempts Because, as I stated in another comment in this thread: That is not how passwords are cracked in today's environment. In today's environment, someone obtains (via hacking or bribes) the internal password hash list, and then runs the list through a system such as this one: https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a270c40 https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27... A "try limit" on the login page does nothing to slow this monster down.