Add observability (monitoring?) to the password guide defenses
Open
Content:Security
- Dominant language
- Markdown
- Stars
- 11k
- Forks
- 23.2k
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 331
Description
-> https://front-end.social/@evaristegal0is@mastodon.social/115491441689522188
> Observability should be added to the section Defenses. Guessing and credential stuffing attacks can easily generate a huge spike of 401 status codes in the authentication endpoint's events. Often, credential stuffing doesn't reach any anti-brute force limit and doesn't return any error (500), so 401 should be monitored.
...seems like a good suggestion (cc @luigigubello ).
Contributor guide
Assessment
This issue has not been assessed yet.