Implement bruteforce defense #18

Open
opened 2021-11-09 11:56:21 +00:00 by glyph · 0 comments
Owner

As briefly discussed in PR#17.

Two options (neither exhaustive nor mutually exclusive): 1) restrict the number of failed consecutive login attempts for peach-web (for example, 10 failed attempts and then you have to request a password reset); 2) use a service such as Fail2ban for broader-spectrum bruteforce protection.

As briefly discussed in [PR#17](https://git.coopcloud.tech/PeachCloud/peach-workspace/pulls/17). Two options (neither exhaustive nor mutually exclusive): 1) restrict the number of failed consecutive login attempts for peach-web (for example, 10 failed attempts and then you have to request a password reset); 2) use a service such as Fail2ban for broader-spectrum bruteforce protection.
glyph added the
enhancement
peach-web
labels 2021-11-09 11:56:21 +00:00
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: PeachCloud/peach-workspace#18
No description provided.