Increased security measure - Password Lockout

Mark Gabriel (Product Manager) - 7 June 2013

If you've forgotten your Objective Connect password recently you may have inadvertently discovered one of you latest security improvements called password lockout. What this means is if anyone attempts to log into your account and fails five times in a row during a five minute period, then your account will become locked for 15 minutes.

The message shown in the Connect interface is shown below. Note that it does not give away any information about the potentially locked account that a hacker could use to their advantage. After 15 minutes your account will return to normal and you can log in with your usual password (or maybe reset it if you still can't remember).

The reasoning behind this change it to make it much harder for people to attempt brute force attacks on guessing your password. With this new safeguard in place, an attacker will only able to guess a maximum of 20 passwords per hour, which would take them a while. Our security monitoring systems will pick up the abnormal activity on an account and alert our systems administrators.



Comments

Post has no comments.

Post a Comment






Captcha Image