4 ms·
In this age of massive botnets, I don't see the point of grouping the requests by IP address, as he suggests: the attacker will just use his 500000 different ma
by ned 18y ago
In this age of massive botnets, I don't see the point of grouping the requests by IP address, as he suggests: the attacker will just use his 500000 different machines to attack a single account.
So you should probably keep track of the username or account ID that the request is being made for, and rate limit on that.