ArchitectureSecurity model
The limit on failed sign-ins
After 10 failed sign-ins in 5 minutes, the server refuses each sign-in for a short time.
A person tries wrong passwords. The server counts each failure.
1 / 4
The limit makes it slow to guess the password. It applies to sign-ins and to attempts to create the account.
| Rule | Value |
|---|---|
| Failures before the refusal | 10 in 5 minutes |
| Answer during the refusal | 429 too_many_attempts |
| End of the refusal | When the oldest failure is 5 minutes old |
The limit is not per IP address
The server has one counter for all callers. A person who can reach the API can thus delay the sign-in of the administrator. This is one more reason to keep the API on localhost or behind HTTPS.
What to do
Keep the API away from the internet. See What listens where and Reach the API through SSH.