Hacker News new | ask | show | jobs
by fortran77 820 days ago
Wow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.
2 comments

Krebs notes that the recovery form does have some form of CAPTCHA on them, which mostly just goes to show that CAPTCHA systems are a poor and increasingly deficient rate limiter.

ETA: Also from a user experience even once a week between attempts is still enough to deeply annoy a user getting popups on their devices. This is one of those cases where rate limits probably still can't solve the user irritation.

That would allow me to log you out of your accounts
No, it would affect login status. Just a delay between reset attempts.

No reset actually occurs until one prompt is accepted.