Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you throttle your password validations, a large enough attack will effectively be a DOS attack anyway since it would be processing more invalid than valid requests, even if your server is "still working".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: