Security · Estimate

A login endpoint limits each IP address to 10 attempts a minute. A botnet with 10,000 IP addresses runs a credential-stuffing attack. How many attempts an hour can it make?

hard Estimation Resilience

Answer

About 6,000,000 login attempts per hour. In review, anything from 4,000,000 to 9,000,000 counts as right.

The worked estimate

10,000 IPs × 10 a minute = 100,000 a minute; × 60 = 6,000,000 attempts an hour. Per-IP limits alone barely slow a botnet. Add limits per account, watch for global spikes in failed logins, check passwords against breached lists and require a second factor.

Numbers: Numbers to know.

Review this in your daily deck All cards in Security