Quote:
Originally Posted by Kushan
I see it on quite a lot of login pages after a failed attempt or two. I'd prefer that over a lockout period.
|
Yes, after one or two failed logins it makes sense, to prevent automated attacks as well as intentional DoS. But not after a successful login... Unless it's some cheap alternative to 2-factor authentication?