So I figured I'd ask what thought you've given to security of accounts, for instance do you have a method to block/prevent random scripted dictionary based attacks on accounts (Similar to what was done here http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html ) ? Reply to comment
We don't have anything in at present, but rate-limiting is on the list for the Wasabi release. This won't entirely stop scripted attacks, but will limit the number of login attempts they can try to something small enough that the vector becomes ineffective (say 5 per minute).
Jeff and I (the only ones with admin access) also have very long random character and symbol passwords that would be very very hard to crack. Reply to comment
If you don't have an account, you'll need one. We recognize that this is a pain, but we do it to keep spambots from flooding the site. If this really bothers, you, please let us know. We're listening!
Jeff and I (the only ones with admin access) also have very long random character and symbol passwords that would be very very hard to crack. Reply to comment
If you don't have an account, you'll need one. We recognize that this is a pain, but we do it to keep spambots from flooding the site. If this really bothers, you, please let us know. We're listening!