getodk / getodk/docs

Describe how Central protects passwords from brute force attacks

Open
#1,499 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
58
Forks
160
Avg merge
5d 11h
Merged PRs (30d)
12

Description

[This forum thread](https://forum.getodk.org/t/improper-restriction-of-authentication-attempts/38396) brings up rate limiting to protect against brute force password attacks. There are some answers there that are worth surfacing more clearly.

[Some extra notes here](https://docs.google.com/document/d/18ryIG355BnyFWtKcQzPkSva9Wd1dk_dR133OcWWMQfY/edit) (auth required)

Contributor guide

Open the contributing guide

Research direction

Start with the linked forum thread on improper restriction of authentication attempts and review the linked Google Doc for the additional notes. Document clearly how Central protects passwords from brute-force attacks, including the rate-limiting information worth surfacing from those sources; done means the relevant Central documentation explains the protection without requiring those links.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.