Saylua-Archive / SayluaLegacy

Browser Game In Development
saylua.com
GNU Affero General Public License v3.0
2 stars 0 forks source link

Make it harder to brute force user logins #118

Open tiffz opened 7 years ago

tiffz commented 7 years ago

It's no good to have it too easy for someone to just brute force passwords! I wonder if we can try to prevent brute forcing the cookies too. I guess in maybe we could make the session information there long enough that it'd be theoretically impossible to guess before a cookie expired.

NoiSek commented 7 years ago

As long as everyone uses an emoji password I can't see this ever becoming an issue, the character space is just too large to reasonably bruteforce.

NoiSek commented 7 years ago

🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥

tiffz commented 7 years ago

Noddy, it's not safe to post your password publicly online.