5 ms·
> - Isn't that the three above points combined? Or what does "credential stuffing protection" amount to? In our case, we track authentication attempts by IP, e
by Sander_Marechal 3y ago
> - Isn't that the three above points combined? Or what does "credential stuffing protection" amount to?
In our case, we track authentication attempts by IP, even successful authentications. If too many authentications come from the same IP in a short time, even over multiple accounts, we start throttling them first, then denying them. I'm in the B2B SaaS space. We know our customers, our typical load, and we have carved out exceptions for certain large clients with known IPs.
- Aachen 3y agoThanks, that's actually valuable to hear from someone who actually implements this!