DLMousey / OIDC.Core

Toy OAuth + OIDC provider written in .net core
1 stars 0 forks source link

Suspicious login detection #9

Open DLMousey opened 1 year ago

DLMousey commented 1 year ago

Users should be informed when a login attempt (successful or otherwise) is made for their account that could be potentially suspicious. What constitutes a suspicious login is still yet to be defined and will consist of mostly fuzzy criteria that'll be easy enough to spoof but will require quite significant effort on the attacker's part to make it work.

Some initial loose criteria for consideration;

joshghent commented 5 months ago

Hey 👋 Stumbled across this issue from your twitter. I've actually built this already! It supports all of these criteria and more! :) Would love to hear your feedback.

https://loginllama.app