6 Matching Annotations
  1. Mar 2023
    1. You are currently allowing your users to choose their own password, and many of them are using the same password they use on other services. There is no other possible way your users are vulnerable to credential stuffing.
    2. t’s important to emphasise that if you don’t reuse passwords, you are literally immune to credential stuffing.
  2. Mar 2021
    1. The practice of throwing a bunch of purloined user names and passwords at various services to see what sticks is known as credential stuffing, and it’s hit the media industry particularly hard in recent years.

      I don't think I've ever seen a name for this practice before.

  3. Apr 2020
    1. Credential stuffing is the automated injection of breached username/password pairs in order to fraudulently gain access to user accounts.