Join GitHub today
GitHub is home to over 36 million developers working together to host and review code, manage projects, and build software together.Sign up
Tokens can be brute forced if 'Clear failcounter after minutes' is not zero #1578
It appears that if 'Clear failcounter after minutes' is set to a non-zero value, after that timeout expires, any token can be brute forced.
I believe one of two options could be pursued to mitigate this.
Option #1 (more security, less user-friendly):
Option #2 (more user-friendly):
I believe #1 would be easier to implement programatically.
Thanks! Actually we already fixed this here
@droobah here is the workaround: https://www.privacyidea.org/reset-failcounter-using-event-handlers/