|
|
#75853
08/13/2001 9:00 AM
|
Joined: Jul 2000
Posts: 1,349
Member
|
|
Member
Joined: Jul 2000
Posts: 1,349 |
quote: Perhaps it should be, but you're being picky about what's secure and what's not. No site can stand up to a DDOS attack but we'd hardly catergorize it as unsecure because of it.
What's so difficult about it? Obviously it would have to be an 'optional feature' (doesn't everything?), but if there are more than 20 or so failed login attempts to a username, the UBB could then refuse to accept login attempts from that IP / to that Username more than once every 30/60 secs. That way, any brute-forcer that's running will be slowed down to a crawl... 1 attempt every 60 seconds? Expect the password to be cracked in a few YEARS...
Either that, or we're doing to have to start distributing those cute little RSA modulo keychains to all users. 
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 1,153
Joined: July 2001
|
|
|
Forums63
Topics37,583
Posts293,955
Members13,824
| |
Most Online151,614 Nov 14th, 2025
|
|
Currently Online 464
Topics Created 0
Posts Made 0
Users Online 0
Birthdays 13
|
|
|
|
|
|