DEV Community

Discussion on: Block malicious login attempts, but preventing account lock-outs.

 
artis3n profile image
Ari Kalfus

Also, 2FA is the best way to stop bots IMO. Works as an additional layer of defense against someone malicious trying to log into a user's account as well.

Thread Thread
 
tarialfaro profile image
Tari R. Alfaro

If CSRF token could prevent automated logins, wouldn't it also protect against automated registering?