Time-based tokens
Time-based tokens
Posted Jul 31, 2026 14:14 UTC (Fri) by archaic (subscriber, #111970)Parent article: Arch Linux disables AUR package adoption
While no one (or one hundred things) is bulletproof and cat-and-mouse is likely the only long-term solution, having tokens valid for a much more limited time and NOT being valid until some reasonable amount of time has elapsed would be more effective against bots that operate significantly faster than any human can. For example, if you hit that tokenized endpoint X seconds after it was generated, probably not a human. Especially for 2fa. How long does it legitimately take to open your phone and get your key and then type it in and hit send? > 5 seconds presumably. Even if all that is accomplished is bots learning to slow down, I think that could be seen as at least a minor (perhaps merely trivial?) victory.
