-
Notifications
You must be signed in to change notification settings - Fork 56
Open
Description
We should attempt to implement login rate limiting as part of these validation rules, as described in NIST SP800-63b section 5.2.2.
the verifier SHALL implement controls to protect against online guessing attacks.
the verifier SHALL limit consecutive failed authentication attempts on a single account to no more than 100.
Requiring the claimant to wait following a failed attempt for a period of time that increases as the account approaches its maximum allowance for consecutive failed attempts (e.g., 30 seconds up to an hour).
Source: https://pages.nist.gov/800-63-3/sp800-63b.html#throttle
It would also be useful to provide Artisan commands that will remove login bans / delays entirely or for specific users / IPs.
Metadata
Metadata
Assignees
Labels
No labels