Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
gfxmonk
on Nov 21, 2013
|
parent
|
context
|
favorite
| on:
Weak passwords brute forced
If they rate limited per user, you could trivially prevent someone from logging in by pummeling the server with login attempts for their username.
ye
on Nov 21, 2013
[–]
If there are limits per-user and per-IP, they would need a shit ton of IPs to do that to any reasonable number of users.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: