-
Notifications
You must be signed in to change notification settings - Fork 165
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create a brute force login protection module set #94
Comments
@Danelif please advise. |
Alright |
I have read this article carefully https://www.owasp.org/index.php/Blocking_Brute_Force_Attacks and found it very relevant. But some techniques are not included in it. |
@Danelif Thank you, please look at how it is done in Tiki to get some more good ideas. |
@marclaporte In tiki 2FA is done using Google2FA php library. Good idea indeed. Instead of using OTP, in Tiki, we use TOTP. But the only problem is that there is not much documentation and usage I wonder why? |
Some docs: TOTP uses time, so the code changes every 30 seconds. |
@marclaporte I have seen how 2FA works in tiki. It could be great to to the same in cypht |
ok, please proceed as a medium priority. High priority is fixing bugs before adding new features. |
lots of great ideas on this here:
https://www.owasp.org/index.php/Blocking_Brute_Force_Attacks
The text was updated successfully, but these errors were encountered: