Login throttling
Cantor, Scott
cantor.2 at osu.edu
Thu Aug 4 12:29:08 EDT 2016
On 8/4/16, 11:58 AM, "users on behalf of Richard Frovarp" <users-bounces at shibboleth.net on behalf of richard.frovarp at ndsu.edu> wrote:
> Is there anything built in to IdP v3 that can do login throttling?
No.
> This would prevent a
> remote system from doing a DoS against an account, and prevent searching
> for the accounts with a password of "Password1".
I'd love to see evidence anybody still does this, because I don't believe it. Phishing is too simple.
> I have mod_security available to use. I could use that if I knew of all
> of the URLs where a login could be posted.
That depends on the login flow, but for Password, the URLs are essentially the SSO profile endpoints in the system.
-- Scott
More information about the users
mailing list