RSS Feed/News Failed Passkey logins do not trigger login limit

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
29,888
Points
823

Reputation:

If a client has more than 4 failed login attempts with username / email and password within 15 minutes the user account will be limited according to option loginLimit:

1764688170949.webp

This option is not applied though if Passkey logins are performed.

While Passkeys are a lot less vulnerable for brute force attacks, it might still be useful to apply a limit.

Suggested Fix
Also apply the configured limit method for Passkey logins (Preferred)
or
Modify the...

Read more

Continue reading...
 
Status
Not open for further replies.
Top