6 ms·
If they rate limited per user, you could trivially prevent someone from logging in by pummeling the server with login attempts for their username.
by gfxmonk 13y ago
If they rate limited per user, you could trivially prevent someone from logging in by pummeling the server with login attempts for their username.
- ye 13y agoIf there are limits per-user and per-IP, they would need a shit ton of IPs to do that to any reasonable number of users.