wso2 / product-is

Welcome to the WSO2 Identity Server source code! For info on working with the WSO2 Identity Server repository and contributing code, click the link below.
http://wso2.github.io/
Apache License 2.0
748 stars 729 forks source link

Is brute-force protection with device cookies possible (OWASP)? #15466

Closed matthid closed 2 weeks ago

matthid commented 1 year ago

Is your feature request related to a problem? Please describe.

I have read

And ask myself if it is possible to configure the identity-server in a way to mitigate brute-force in a way suggested by OWASP with device cookies? And if not: This is the feature request for it. This would improve the brute-force protection options of the identity-server. If it is: Maybe we can add a section to "mitigate-brute-force-attacks" on how the configuration would look like.

Describe the solution you would prefer

The solutions in the documentation:

Hence the OWASP recommendation would be an improvement over existing solutions. They say:

The protocol is less susceptible to DoS attacks than plain account locking out and yet effective and easy to implement.

Thanks!

isharak commented 2 weeks ago

This issue is being closed due to extended inactivity. Please feel free to reopen it if further attention is needed. Thank you for helping us keep the issue list relevant and focused!