I haven't yet gone through the discussion but would you mind letting me know if you're satisfied with the outcome? You appeared to be fighting for increased privacy, so thank you.
Also you'll see that in my comment, I raised another issue RE: lack of two factor auth. I'm curious, why do you think single factor auth is fine? Simply because brute force for a 30 char password is not practical on todays hardware? Or is there something I'm missing?
- sneak and I have fundamental differences in what we call spyware. The issue that was brought up in that thread is standard analytics events - nothing like stealing passwords or etc.
- Regardless, CapRover uses NetData 1.8 [1] . According to NetData's github page, they added analytics in NetData 1.12 [2] , so even if you're concern with analytics events, this issue won't apply to you anymore.
Regarding two factor auth: CapRover blocks brute-force attacks by limiting number of wrong passwords per minute.
[1] https://github.com/caprover/caprover/blob/48440db14aa115aca1...
RE: 2fa. Brute force protection is a step in the right direction, but passwords can leak in various ways, brute force isn't the only attack vector. I'll comment in the actual two factor auth discussion on the CapRover GitHub issue though.
Brute forcing a 30 char (or even 20 char) password over the network is infeasible. Do the math. Regardless, as the CapRover developer pointed out in a sibling comment, it rate limits attempts, but in the case where you are using a long, random password, it would be fine even if it didn’t.
Brute forcing this, you would have to try every combination. Which means for a four-letter long password: 26x26x26x26 = 456 976 possible passwords.
For a 10 letter long password: 26^10 = 141167095653376 possible passwords.
Clarifying it further is “number of days to brute-force if you can try (eg) 10k requests/sec”.
I kept it to 26 letters to keep the math simpler (or rather - the numbers smaller, for myself, really).
Number of days to brute-force if 10k requests/sec (26 letters still...):
4-length password = 45 seconds
10-length password = 453 years
Please give me a heads up if my math is off.