Summary
The auth service has no protection against brute-force attacks. An attacker can attempt unlimited password guesses with no lockout, delay, or notification.
Recommendation
Progressive Delays
| Failed Attempts |
Response |
| 1-3 |
Normal response |
| 4-5 |
Add 2-second delay before response |
| 6-8 |
Add 5-second delay + CAPTCHA required |
| 9-10 |
Add 30-second delay + CAPTCHA |
| 11+ |
Temporary lockout (15 minutes) |
Implementation
- Track failed attempts per email/IP in Redis with TTL
- Reset counter on successful login
- Send email notification after 5 failed attempts ("Someone is trying to access your account")
- Log all lockout events for security monitoring
IP-Level Protection
- Track failed attempts per IP across all accounts
- Block IP after 50 failed attempts across any accounts in 1 hour
- Maintain an IP reputation score that decays over time
Summary
The auth service has no protection against brute-force attacks. An attacker can attempt unlimited password guesses with no lockout, delay, or notification.
Recommendation
Progressive Delays
Implementation
IP-Level Protection