Skip to content

Add account lockout and progressive delays on failed authentication #25

Description

@PeaStew

Summary

The auth service has no protection against brute-force attacks. An attacker can attempt unlimited password guesses with no lockout, delay, or notification.

Recommendation

Progressive Delays

Failed Attempts Response
1-3 Normal response
4-5 Add 2-second delay before response
6-8 Add 5-second delay + CAPTCHA required
9-10 Add 30-second delay + CAPTCHA
11+ Temporary lockout (15 minutes)

Implementation

  • Track failed attempts per email/IP in Redis with TTL
  • Reset counter on successful login
  • Send email notification after 5 failed attempts ("Someone is trying to access your account")
  • Log all lockout events for security monitoring

IP-Level Protection

  • Track failed attempts per IP across all accounts
  • Block IP after 50 failed attempts across any accounts in 1 hour
  • Maintain an IP reputation score that decays over time

Metadata

Metadata

Assignees

No one assigned

    Labels

    anti-abuseBot detection and abuse preventionenhancementNew feature or requestpriority: highHigh severity findingsecuritySecurity issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions