Sha256: 21e95502d3d7817f7b4140f1e38692461682436827be670314cf264dae8bcda0
Contents?: true
Size: 756 Bytes
Versions: 72
Compression:
Stored size: 756 Bytes
Contents
h3. Authentication security projects for a later date * Track 'failed logins this hour' and demand a captcha after say 5 failed logins ("RECAPTCHA plugin.":http://agilewebdevelopment.com/plugins/recaptcha) "De-proxy-ficate IP address": http://wiki.codemongers.com/NginxHttpRealIpModule * Make cookie spoofing a little harder: we set the user's cookie to (remember_token), but store digest(remember_token, request_IP). A CSRF cookie spoofer has to then at least also spoof the user's originating IP (see "Secure Programs HOWTO":http://www.dwheeler.com/secure-programs/Secure-Programs-HOWTO/web-authentication.html) * Log HTTP request on authentication / authorization failures http://palisade.plynt.com/issues/2004Jul/safe-auth-practices
Version data entries
72 entries across 72 versions & 15 rubygems