4 posts
  • Bought between 1 and 9 items
  • Canada
  • Has been a member for 3-4 years
MrBond says

falls off chair

13 posts
  • Australia
  • Has been a member for 2-3 years
dgoodlad says

[...] Then again, I don’t really see the brute-force issue to begin with. As long as the server implements a delay of say 1 or 0.5 second per login attempt (which is hardly noticable for a legitimate user), that would cause as much as a 7 character password to be quite infeasible to crack. Can anyone enlighten me? Or it a parallel request attack that makes this feasible regardless of the millions of required requests? Or would that cause an effect similar to a DDoS and backfire on the attackers?

Instead of thinking about a distributed dictionary attack against a single user trying many passwords, consider an attack against many users trying few simple passwords. Lots of people out there still use trivial passwords, which is what that kind of attack is targeting.

In the case of a distributed attack against many user accounts, it’s very difficult to track and identify malicious login attempts versus legitimate ones. A delay between login attempts doesn’t help with this style off attack either, sadly.

Dave

53 posts Master of the Internets
  • Australia
  • Bought between 10 and 49 items
  • Exclusive Author
  • Grew a moustache for the Envato Movember competition
  • Has been a member for 3-4 years
  • Referred between 1 and 9 users
chendo says

@chendo while ur at it, is it hard to make the “Logout” button kill the users session on ALL marketplaces? not just the one they click logout on?

It’s on the books.

2077 posts
  • Gold Mo Grower
  • Sold between 5 000 and 10 000 dollars
  • Most Wanted Bounty Winner
  • Author had a Free File of the Month
  • Interviewed on the Envato Notes blog
  • Has been a member for 4-5 years
+7 more
DarkstarDesigns says

They are so hard to read it often take four or so attempts to get it right, they dont need to be so hard!

1989 posts
  • Elite Author
  • Sold between 250 000 and 1 000 000 dollars
  • Author had a File in an Envato Bundle
  • Has been a member for 4-5 years
  • Author had a Free File of the Month
  • Won a Competition
  • Bought between 10 and 49 items
+4 more
bitfade says

cloud9communication
cloud9communication Recent Posts
Threads Started
595 posts
  • India
  • Sold between 10 000 and 50 000 dollars
  • Bought between 10 and 49 items
  • Exclusive Author
  • Referred between 10 and 49 users
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Has been a member for 4-5 years
cloud9communication says

now its great earlier i had to zoom in my screen to read the CAPTCHA

3650 posts Community Moderator
  • Has been a member for 5-6 years
  • Contributed a Tutorial to a Tuts+ Site
  • Netherlands
  • Community Moderator
  • Microlancer Beta Tester
  • Sold between 10 000 and 50 000 dollars
  • Repeatedly Helped protect Envato Marketplaces against copyright violations
  • Exclusive Author
+4 more
Joost Volunteer moderator says

Instead of thinking about a distributed dictionary attack against a single user trying many passwords, consider an attack against many users trying few simple passwords

if there are 10,000 current password guesses getting fired at the server, then the server has to keep those 10,000 requests open while the delay runs. it wouldn’t really achieve anything with the delay other than putting more load on the server.

Ah, those are interesting viewpoints. Didn’t look at it like that. You’re both absolutely right, and luckily using reCaptcha does indeed solve these issues effectively :) Thanks again for looking after us, devs!

6 posts
  • Bought between 1 and 9 items
  • Has been a member for 3-4 years
tomato1 says

LOL @9GAG post..I like the changes by the way…

8119 posts Community Moderator
  • Attended a Community Meetup
  • Community Moderator
  • Has been a member for 6-7 years
  • United Kingdom
  • Contributed a Tutorial to a Tuts+ Site
  • Won a Competition
  • Contributed a Blog Post
  • Beta Tester
  • Bought between 50 and 99 items
+4 more
MSFX Volunteer moderator says

so i’m logged into AD and when I go to TF i’m logged out… thought this was fixed?

422 posts
  • Bought between 10 and 49 items
  • Exclusive Author
  • Has been a member for 2-3 years
  • Interviewed on the Envato Notes blog
  • Most Wanted Bounty Winner
  • Romania
  • Sold between 10 000 and 50 000 dollars
studio_21 says

Cool, less annoying.

by
by
by
by
by
by