nanog mailing list archives
Re: gmail security is a joke
From: Rich Kulawiec <rsk () gsp org>
Date: Fri, 29 May 2015 21:31:02 -0400
On Fri, May 29, 2015 at 12:32:34PM -0400, Justin M. Streiner wrote:
There are providers (banks, etc) who will disable an online account that has had X failed login attempts. While that's good for preventing $bad_guy from continuing to try to brute-force-guess the password, it creates a nominal DoS condition for the legitimate owner who then has to contact the provider and go through their password reset procedure.
This is why automatic lockout procedures are a problem for some operations, particularly those which are known to create user account names based on algorithms like "first initial + last name, truncated to 8 characters". It's not at all difficult to construct a list of valid (or probably-valid) usernames at such sites, hit them all repeatedly from distributed botnets (N-1 times from any one address, where N times would trigger IP-based blocking methods) and thus effectively DoS a decent fraction of the users. ---rsk
Current thread:
- Re: gmail security is a joke, (continued)
- Re: gmail security is a joke Rich Kulawiec (May 28)
- Re: gmail security is a joke Joe Abley (May 28)
- Re: gmail security is a joke Peter Beckman (May 29)
- Re: gmail security is a joke Richo Healey (May 29)
- Re: gmail security is a joke Sander Steffann (May 29)
- Re: gmail security is a joke Barry Shein (May 29)
- Re: gmail security is a joke Valdis . Kletnieks (May 29)
- Re: gmail security is a joke Owen DeLong (May 29)
- Re: gmail security is a joke Jimmy Hess (May 29)
- Re: gmail security is a joke Justin M. Streiner (May 29)
- Re: gmail security is a joke Rich Kulawiec (May 30)
- RE: gmail security is a joke Thijs Stuurman (May 26)
- Re: gmail security is a joke Harald Koch (May 26)
- Re: gmail security is a joke Anil Kumar (May 26)
- Re: gmail security is a joke Valdis . Kletnieks (May 27)
- Re: gmail security is a joke Rafael Possamai (May 27)
- Message not available
- Re: gmail security is a joke Larry Sheldon (May 27)
