3 ms·
What is stopping companies from implementing timers to prevent brute force attacks? Limit password entry attempts to 3 then if still wrong then wait 1 minute. O
by Evolved 12y ago
What is stopping companies from implementing timers to prevent brute force attacks? Limit password entry attempts to 3 then if still wrong then wait 1 minute. One more wrong entry then wait 3 minutes then 15 minutes then 1 hour, 4 hours, 8 hours, 24 hours etc.
Doesn't iOS do this if you don't have "erase data after 10 failed attempts" set?
Why can't all systems have this implemented or is this bypassed another way which then allows someone to brute force to their heart's content?
- jMyles 12y ago1) This article seems to describe actually having physical access to the device. 2) As for "all systems," if you mean a place where public guessing is possible (like a web app), then this measure opens up an easy DOS surface. Want someone not to be able to access their account? Know their email / username? Just burn up all their 'guesses' and they'll have to wait.
- Evolved 12y agoGood points. What do you think about a 2FA-type of setup where if someone tries this then it sends a message to the device that asks if you are trying to access something through a webapp and if you say no then it blocks access until the correct password is entered or until it is accessed from the same device that previously successfully accessed it on a consistent basis (say 5 times within the past week or month). Could IP-blocking be implemented or a double timer where if someone tries to DoS the account by entering too many passwords too quickly then that is also limited such as trying to submit too many comments to HN too quickly?