Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

GitLab adds further measures to combat credential stuffing and other types of platform abuse

Blog post from GitLab

Post Details
Company
Date Published
Author
Monmayuri Ray
Word Count
445
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

Amid an increase in credential stuffing attacks, GitLab has enhanced user authentication processes by integrating Arkose Protect, a security solution from Arkose Labs, into its login flow to help mitigate these threats. Although multifactor authentication (MFA) is recommended and reduces the likelihood of such attacks, it is optional for users, prompting GitLab to implement additional protective measures. The integration, which went live on April 29, 2022, involves assessing user sessions with a machine learning model that classifies risk as high, medium, or low. Users deemed low risk proceed without disruption, while those at higher risk complete an enhanced CAPTCHA. These measures have significantly reduced account takeovers, spam, and crypto mining abuses by over 40%. GitLab's anti-abuse team continues to refine its strategies and plans to introduce a holistic user scoring engine to further secure the platform while minimizing inconvenience for legitimate users.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.