Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Thanuja Jayasinghe
Hi Farasath, On Tue, Jun 21, 2016 at 2:57 AM, Farasath Ahamed wrote: > Hi Thanuja, > > > On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe > wrote: > >> Hi All, >> >> I'm working on $subject. >> >> We are planning to prevent this flow from brute force

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Prabath Siriwardana
This thread is also related to [Architecture][Dev][IS] Improvements in handling incorrect login attempts [1]. [1]: http://wso2-oxygen-tank.10903.n7.nabble.com/Dev-IS-Improvements-in-handling-incorrect-login-attempts-td138672.html Thanks & regards, -Prabath On Mon, Jun 20, 2016 at 1:05 AM,

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Farasath Ahamed
Hi Thanuja, On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe wrote: > Hi All, > > I'm working on $subject. > > We are planning to prevent this flow from brute force attacks by enabling > followings, > >1. Enable captcha/reCaptcha after n failed attempts >2. Lock

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Malithi Edirisinghe
Hi Thanuja, On Mon, Jun 20, 2016 at 7:55 PM, Thanuja Jayasinghe wrote: > Hi Darshana, > > On Mon, Jun 20, 2016 at 6:54 PM, Darshana Gunawardana > wrote: > >> Hi Thanuja, >> >> On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe >> wrote:

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Thanuja Jayasinghe
On Mon, Jun 20, 2016 at 7:55 PM, Thanuja Jayasinghe wrote: > Hi Darshana, > > On Mon, Jun 20, 2016 at 6:54 PM, Darshana Gunawardana > wrote: > >> Hi Thanuja, >> >> On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe >> wrote: >> >>> Hi

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Thanuja Jayasinghe
Hi Darshana, On Mon, Jun 20, 2016 at 6:54 PM, Darshana Gunawardana wrote: > Hi Thanuja, > > On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe > wrote: > >> Hi All, >> >> I'm working on $subject. >> >> We are planning to prevent this flow from brute force

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Darshana Gunawardana
Hi Thanuja, On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe wrote: > Hi All, > > I'm working on $subject. > > We are planning to prevent this flow from brute force attacks by enabling > followings, > >1. Enable captcha/reCaptcha after n failed attempts >2. Lock the

Re: [Architecture] [IS] Block brute force attacks on password recovery flows

2016-06-20 Thread Isura Karunaratne
Hi Thanuja, On Mon, Jun 20, 2016 at 1:35 PM, Thanuja Jayasinghe wrote: > Hi All, > > I'm working on $subject. > > We are planning to prevent this flow from brute force attacks by enabling > followings, > >1. Enable captcha/reCaptcha after n failed attempts >2. Lock the