How to Prevent Account Takeover Attacks - John Chirhart - ASW #109
Jun 1, 2020
35:26
forum Ask episode
view_agenda Chapters
auto_awesome Transcript
info_circle Episode notes
Attackers are using methods such as password spraying and credential theft to commit fraud against websites at an alarming rate. Automated bots are aiding the attacker to conduct these operations at scale. Your defensive strategy should include a mechanism to determine if a session is being controlled by a real user or a bot. How can we best accomplish this without creating too much friction between the real users and your web applications?