Ask HN: What to do when a botnet is requesting password resets?
6 points| Fabricio20 | 5 years ago | reply
I have contacted the service in particular (part of GAFAM) and their account security department told me there is nothing that can be done in this case and I should just disregard the emails.
I now ask you, HN, what can _we_ as developers, do to prevent this from happening on our services? Limit the amount of password reset requests for an account? (still doesn't solve the issue), etc.. As I, genuinely, have not managed to come up with a solution.
[+] [-] some_furry|5 years ago|reply
That's what developers can do. What developers should do is consider what prevents their customer support funnel from getting overloaded.
[+] [-] benologist|5 years ago|reply
I think letting users define restrictions on their accounts would help too, like a firewall for which countries or cities etc can access their account, schedules for when signing in can occur or when it is disabled etc. Most people could just select their city and waking hours.
[+] [-] unknown|5 years ago|reply
[deleted]
[+] [-] unknown|5 years ago|reply
[deleted]
[+] [-] atrilumen|5 years ago|reply