3 ms·
> How do you prevent credential stuffing attacks? CAPTCHAs don't work anymore, at this point. AI can trivially solve them. Rate-limit the number of attempts,
by JoshTriplett 1mo ago
> How do you prevent credential stuffing attacks?
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
- gruez 1mo ago>CAPTCHAs don't work anymore, at this point. AI can trivially solve them. The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
- GoblinSlayer 1mo agoFor credential stuffing you need only one attempt.
- gruez 1mo agoNo, it's a numbers game on both sides. Attackers are after hundreds or thousands of accounts, not just one. Defenders knows that exactly 0 hacks are impossible to achieve, and they're just trying to limit losses from fraud, but also costs from anti-fraud.
- GoblinSlayer 1mo agoThey have so many accounts broken daily? Then credential stuffing attacks are not prevented.
- olyjohn 1mo agoThen you don't need to automate it, and you can just manually solve the captcha and log in.
- bellowsgulch 1mo agoThere is no raised cost anymore. Every professional doing this work has perfect alignment with regular consumer heuristics. OS, browser, fingerprinting, networked bytes, residential address spaces. All of it is done.
- nisegami 1mo ago>How do you prevent credential stuffing attacks? Passkeys or magic links seem like the way forward here.
- hombre_fatal 1mo agoYou can also randomly generate a password for the user on the form they'd normally type one in on registration. Add a "Regen" button to give users more visceral control over it before they submit the form.
- account42 1mo agoThat's essentially the same as magic links because most users won't remember/save that password and will have to rely on the usually email-based reset flow.
- hombre_fatal 1mo agoSure, but this subset of user was going to otherwise reuse their password and be susceptible to cred-stuffing. The point is to stop the attack and prevent users from accidentally hosing themselves.
- nisegami 1mo agoIsn't that essentially a manual passkey?
- JoshTriplett 1mo agoPlease don't. I find such services obnoxious, especially when they aggressively log you back out. Chasing down a link in your email is much slower than having your password manager fill in the long unique random password and hitting "log in".
- nisegami 1mo ago>Chasing down a link in your email is much slower than having your password manager fill in the long unique random password and hitting "log in". That's basically a passkey without its special API.
- vablings 1mo agoPasskey only. No passwords no usernames just passkey
- olyjohn 1mo agoAt the minimum, stop using goddamn email addresses for the login.
- Plont 1mo agoI'm not giving up recovery codes, nor my ability to default to locking out people who physically have my device. I usually don't allow auto-login or biometrics login either. If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it. I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
- vablings 1mo agoTwo passkeys. If you lose two then yeah, you are boned don't do that. They are absolutely the superior solution