Hacker News new | ask | show | jobs
by plextoria 10 days ago
This intrigued me and I topped up an account. Is there no password? Anyone could "steal" my account number and kick me out?
1 comments

There is no password, just like Mullvad. You should "protect" your account number like you would a password, but also, you can just discard it and change to another one in a month, for example.
Thanks for your answer! Makes me curious how do you defend against people simply bruteforcing or guessing the account numbers.
Rate limiting when it's invalid (and high entropy to generate new ones)! It's in the FAQ :)