Hacker News new | past | comments | ask | show | jobs | submit login

Hey everyone I want to share my personal and real-world experience about credential stuffing attacks. These are very hard to solve because fundamentally it's users fault, especially the ones with password-reuse habit. Nevertheless we responsible developers are the ones who should keep the internet safe, so feel free to chime in, evaluate my solutions and maybe we come up with "the" best practice against this type of attacks.

If there's interest I want to make this into a library and open source a django-specific solution as it's my everyday framework. The discussion applies to ALL web frameworks.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: