Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> What am I missing? Fail2ban has been around a long time.

Modern threat actors can spread requests out over large pools of source IPs. Rate limiting login attempts by IP isn't an effective means of preventing credential stuffing attacks.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: