Hacker News new | ask | show | jobs
by mlosapio 2948 days ago
I’m available for basic security consultancy.

- MFA for initial logins - captcha for repeated attempts - IP based heuristics to detect fraud

I feel like these places invest very little in securing their platform.

I have to hope that the URLs for the objects stored in the cloud (s3) are at least time-bound and signed.