Open codeling opened 10 years ago
As elaborated a bit in this comment, one or more policies determining an adaptive number of allowed failed attempts might be useful against distributed brute force attacks.
Current Ideas for adapting the allowed numbers of failed logins include:
This would more or less follow similar ideas as Risk-Based Authentication (RBA).
As elaborated a bit in this comment, one or more policies determining an adaptive number of allowed failed attempts might be useful against distributed brute force attacks.