|
|
|
|
|
by FrenchDevRemote
1512 days ago
|
|
>yes obviously there are people out there with fully automated systems who will try massive lists of commonly used plaintext passwords for authentication if you don't throttle/rate-limit it. and those people use single browser/single useragent/single browser fingerprint/single IP the people competent enough to send millions of requests are usually also competent to send hard to detect requests there are dozens of (free)tools/services offering those capabilities for LEGITIMATE purposes(like scraping) there is an even bigger underworld market for paid tools for illegitimate purposes |
|
even if you see something like a single /32 address that is probably the public facing endpoint of a mobile phone carrier's cgnat and has MANY users behind it, trying different password attempts, you can still rate limit the number of attempts per unique username.
the actual amount of legit requests that a human who has forgot their password makes is 99.9% of the time under ten requests per account before they give up.