Hacker News new | ask | show | jobs
by BrunoBernardino 14 days ago
There is no password, just like Mullvad. You should "protect" your account number like you would a password, but also, you can just discard it and change to another one in a month, for example.
1 comments

Thanks for your answer! Makes me curious how do you defend against people simply bruteforcing or guessing the account numbers.
Rate limiting when it's invalid (and high entropy to generate new ones)! It's in the FAQ :)