Comment on Authy got hacked, and 33 million user phone numbers were stolen

<- View Parent
sudneo@lemm.ee ⁨6⁩ ⁨months⁩ ago

Lack of rate limiting is a code vulnerability if we are talking about an API endpoint.

Not that discussion makes any sense at all…

Also, “not securing” doesn’t mean much. Security is not a boolean. They probably have some controls, but they still have a gap in the lack of rate limiting.

source
Sort:hotnewtop