4 ms·
In some period of time a user is only able to do some amount of login attempts, after that he has to wait until he can try again to login. You can do that per I
by asdfor 16y ago
In some period of time a user is only able to do some amount of login attempts, after that he has to wait until he can try again to login. You can do that per IP or per username, doing it per username its not good because someone can abuse that to block the genuine user to log in. Doing it per ip is the best option you have and i didn't say that its not good, what i said is that if the user uses a weak password even if you put a rate limit they will be able to find the password soon enough.