Describe how Central protects passwords from brute force attacks
- Dominant language
- Python
- Stars
- 58
- Forks
- 160
- Avg merge
- 5d 11h
- Merged PRs (30d)
- 12
Description
[This forum thread](https://forum.getodk.org/t/improper-restriction-of-authentication-attempts/38396) brings up rate limiting to protect against brute force password attacks. There are some answers there that are worth surfacing more clearly.
[Some extra notes here](https://docs.google.com/document/d/18ryIG355BnyFWtKcQzPkSva9Wd1dk_dR133OcWWMQfY/edit) (auth required)
Contributor guide
Research direction
Start with the linked forum thread on improper restriction of authentication attempts and review the linked Google Doc for the additional notes. Document clearly how Central protects passwords from brute-force attacks, including the rate-limiting information worth surfacing from those sources; done means the relevant Central documentation explains the protection without requiring those links.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100