Kara
kara.systems
Kara
@kara.systems
Security researcher / Counterintelligence
no, i didn't say I have evidence to anyone able to bruteforce it. but, given that the string is too short, it is easy to do so.

all i suggest is to increase the size of the string and complexity.
April 28, 2023 at 2:13 AM
yes. that is the best way because it makes the cost of bruteforce unsustainable.
April 26, 2023 at 8:29 PM
first of all, bruteforce doesn't only mean a user hitting an endpoint of Bsky API. It also mean using enough codes, say scrapped online to find patterns and reverse engineering the algo.

Second, blanket banning IP won't help because most proxies don't operate based IP quota.
April 26, 2023 at 8:28 PM
Have you heard of proxy rotation? Rate limiting won't help with that.
April 26, 2023 at 9:45 AM
Opportunity
April 26, 2023 at 9:43 AM
Nahiko!!!!
April 26, 2023 at 6:29 AM
Also, "bsky-social-" part might be redundant, but I understand the need to have bsky mentioned.

But, it also allows visibility to coders on social media to search and add to their bruteforce mechanism.
April 26, 2023 at 4:22 AM
I have seen reports of so coders are trying to bruteforce the invitation codes.

I would suggest adding a bit more HEX variations to the code generation.
April 26, 2023 at 4:17 AM