From @bhcrosslake on January 12, 2017 0:35
As a DFSP, I don't want other DFSPs to get a complete list of my user numbers.
This could be possible through a brute force attack on the SPSP Server. To prevent that, the SPSP server should implement a circuit breaker to throttle queries from DFSPs that repeatedly try user numbers that don't exist.
Acceptance Criteria
This is a relatively low priority story as it doesn't involve money gain/loss. It may ignored if it is accomplished through the central hub. see #336
Copied from original issue: LevelOneProject/Docs#337
From @bhcrosslake on January 12, 2017 0:35
As a DFSP, I don't want other DFSPs to get a complete list of my user numbers.
This could be possible through a brute force attack on the SPSP Server. To prevent that, the SPSP server should implement a circuit breaker to throttle queries from DFSPs that repeatedly try user numbers that don't exist.
Acceptance Criteria
This is a relatively low priority story as it doesn't involve money gain/loss. It may ignored if it is accomplished through the central hub. see #336
Copied from original issue: LevelOneProject/Docs#337