Security Control Framework
How GitLab is fighting credential stuffing and platform abuse

How GitLab is fighting credential stuffing and platform abuse

8/19/2022 · Monmayuri Ray

What this post added

This post details the implementation of Arkose Protect into the user login flow to combat credential stuffing attacks, spam, and crypto mining abuse. It describes the risk assessment process involving IP address, user activity, and failed login attempts, and the use of enhanced CAPTCHAs for higher-risk sessions. The post also mentions future plans for a holistic user scoring engine.

Read the original post ↗