Hacker News new | ask | show | jobs
by themoonisachees 933 days ago
The threshold is lower but in reality it still makes considerably more login attempts, many of them failed, than a normal client ever would. Credential stuffing attacks don't really limit themselves to a single account, even if it worked.