Learning path

Full curriculum

Full curriculum

Unit content

Online authentication guessing and rate limiting

An online authentication service can test each login attempt against the real verifier, so an attacker may automate repeated guesses unless the service constrains them.

Unlike an offline attack against stolen verifier data, the defender can observe online attempts and impose policy before each new guess.

Useful controls include

  • rate limits per account, credential source or broader risk signal;
  • increasing delays after repeated failures;
  • temporary challenge or step-up authentication;
  • monitoring for distributed guessing across many accounts.

A permanent account lockout after a few failures can itself become a denial-of-service primitive: an attacker may intentionally lock other users out.

Recovery flows deserve the same treatment as login. A short-lived reset link or one-time code is also an authentication credential while it remains valid.

Online controls limit guesses sent through the legitimate service. They do not protect stored verifier data after theft; credentials stored for verification need separate defenses against offline guessing.