Tomasz

My feedback

2 results found

  1. 2 votes
    1 comment  ·  Compass  ·  Admin →
    How important is this to you?
    An error occurred while saving the comment
    Tomasz commented  · 

    Locking the account that has had N unsuccessful login attempts (where N is configurable parameter) would be somewhat double-edged: someone would need to go and unlock the account (= extra work for the helpdesk). In addition, it could be abused to DoS the account of friend you don't like so much.
    Having said that a softer alternatives are possible: locking out the account for short period of time: say 10 mins or implementing some throttling to reduce the number of attempts an adversary may take

    Tomasz supported this idea  · 
  2. 9 votes
    0 comments  ·  Atlas » Alerts  ·  Admin →
    How important is this to you?
    Tomasz supported this idea  · 

Feedback and Knowledge Base