Hacker News new | ask | show | jobs
by sjadoinqwoeihad 1070 days ago
You can't ratelimit someone you have not yet identified. Unless their username is also a password. But then you just have 2 passwords. And the ID password would have to be sufficiently high entropy to not be hit by bots.