The Blog

4 Comments

Got something to say? Feel free, we want to hear from you! Leave a Comment

  1. iJeff says:

    The person who wrote this article sounds brilliant. I would have his babies if that option was available.

  2. Grateful says:

    Thanks for posting this, it addressed all the questions I had…and a few I didn’t. Porting to Ruby commencing now…

  3. Thanks for your excellent thoughts. I used them as underlying principles for a new WordPress plugin, http://wordpress.org/extend/plugins/login-security-solution/.

    You suggest deleting the failed login data once the user logs in successfully. But what if the attacker got lucky and gets in? I decided to have a cutoff on the number of failed logins after which if they do log in, I immediately force them out and require they use the lost password process. This verifies their identity via email on record and prevents damage from being done.

Trackbacks for this post

  1. Principles to Apply When Preventing Brute Force Attacks | Ian Dunn

Leave a Comment

Let us know your thoughts on this post.

Heads up! You are attempting to upload an invalid image. If saved, this image will not display with your comment.