Skip to main content
New Idea

Prevent hackers from brute force guessing customer passwords

  • March 4, 2022
  • 1 reply
  • 24 views

James.Bredenhof
Contributor
Forum|alt.badge.img+1

Freshworks should have tools to discourage brute force hackers. Example lock account for 15 minutes after 5 failed login attempts, etc.

 

Today, if a hacker goes to our helpdesk, they can:
a) get my customer email address (username) from LinkedIn, press releases etc.
b) brute force the password, because there are no limits to the number of password attempts

1 reply

James.Bredenhof
Contributor
Forum|alt.badge.img+1

EDIT: I was extremely concerned about this, so did some experimentation with my “fake customer” account login.
Despite what I was told by FreshDesk Support, it appears that there ARE some tools to prevent brute force logins. After a few failed logins, it prompts that

“3 login attempts left.
The email and password does not match
As a safety measure, your account may get locked temporarily. It is recommended that you use forgot password.”

 

So it appears that this is already in place.