Hacker News new | past | comments | ask | show | jobs | submit login

Why not lock the account for 30 minutes after 6 failed attempts?



That would make it quite easy to maliciously lock someone out.

Instead locking accounts, appropriate throttling might be a better idea.


Throttling can still result in an effective DoS for the affected user, as they get stuck in the queue behind the brute force attempts. Throttling based on source address is not practical either given many brute force attempts use many hacked hosts as their sources to get around this very sort of limit.


Which is a big concern for internet accassable things. However if you password entry is a physical device it works great.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: