Other than allowing at least 14,000 login attempts from the same system without blocking suspicious activity. Nor using services like haveibeenpwned to prevent users from reusing passwords.
Other than allowing at least 14,000 login attempts from the same system without blocking suspicious activity. Nor using services like haveibeenpwned to prevent users from reusing passwords.
> Do they know about every breach out there without fail?
They know about a lot of them. I'd hazard a guess that at least three quarters of the affected accounts would have been in HIBP, probably far more.
How would you detect that these requests are coming from the same "system?"
HIBP only knows about breaches that are made public. Based on the current evidence, this was not a breach that was made public. It was a breach being sold.
A smart attacker would spread the logins out over a large number of devices and a long period of time to avoid detection.
> The term computer system may refer to a nominally complete computer ... or to a group of computers that are linked and function together
The only thing that I added was "that are distinguishable" because you implied that the server ought to be able to tell that this is a coherent attack by a single system and not just normal traffic from unrelated systems.
If victim hosts do not have enough information to recognize the disparate computers as part of a botnet, then from the perspective of the attacked host the computers are separate systems.
I try to assume that people are interacting in good faith, but it's getting very difficult. Have a nice day!
That said, I'm shadow banned so you should probably ignore my advice on HN guidelines.