OpenConext / Stepup-SelfService

Stepup Self-service interface
Apache License 2.0
2 stars 5 forks source link

Prevent brute-forcing of SMS challenge #385

Closed phavekes closed 2 hours ago

phavekes commented 2 hours ago

This issue is imported from pivotal - Originaly created at Feb 12, 2015 by Reinier Kip

Currently, the SMS challenge could theoretically be brute-forced, as no constraint on number of challenge entries is in place.

phavekes commented 2 hours ago

Non-configurable 10 to keep in line with OWASP advisories. (Daan van Renterghem - Feb 19, 2015)