Anatomy of a Credential Stuffing Attack
Credential stuffing is not brute force. Understanding the difference is what makes it detectable — and what makes most rate limits useless against it.
- credential-stuffing
- authentication
- detection
7 min read
Credential stuffing is not brute force. Understanding the difference is what makes it detectable — and what makes most rate limits useless against it.
The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.
MFA is either “a magic switch that ends hacking” or “already broken, why bother”, depending on who you ask. Both are wrong. Here is the honest version — what it kills stone dead, what walks straight past it, and which kind to actually turn on.