Replay attacks #54
Replies: 2 comments 3 replies
-
Hi @florian-milky, |
Beta Was this translation helpful? Give feedback.
-
@florian-milky we introduced |
Beta Was this translation helpful? Give feedback.
-
Hi @florian-milky, |
Beta Was this translation helpful? Give feedback.
-
@florian-milky we introduced |
Beta Was this translation helpful? Give feedback.
-
I've been considering using BotD to mitigate malicious attacks such as card testing.
IMO BotD can be an alternative to Captcha.
What I am missing from the docs is that I would like to prevent a potential attacker to generate a legit requestId and then use this requestId in every API call.
Google captcha for example lets you use the request token only once with a validity of 2 minutes.
See their docs:
Is this something that could be in your roadmap?
Beta Was this translation helpful? Give feedback.
All reactions