4 ms·
See "Part VII" of this SO answer from Jeff Atwood describing mitigation techniques for "distributed brute force attacks" http://stackoverflow.com/questions/549
by evanspa 13y ago
See "Part VII" of this SO answer from Jeff Atwood describing mitigation techniques for "distributed brute force attacks"
http://stackoverflow.com/questions/549/the-definitive-guide-to-form-based-website-authentication http://stackoverflow.com/questions/549/the-definitive-guide-...
TL;DR - compute the average number of system-wide failed password attempts, and if it's over the norm, impose small delay on all users (except those that login via a persistent login cookie).
- rurounijones 13y agoVery useful, thanks!
- jakobe 13y agoActually, this answer isn't by Jeff Atwood. See http://meta.stackoverflow.com/questions/95172/old-problematic-question-edit-or-delete http://meta.stackoverflow.com/questions/95172/old-problemati...
- evanspa 13y agoAh - my mistake. Thank you for clarifying.
- ohwp 13y agoNote that this can be very tricky. You don't want to keep connections open or waiting.