Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

A site I know allows 5 login attempts per hour. That seems plenty for legitimate purposes. I've never heard anyone complain.


But it doesn't matter if they keep hitting their service with a list of known emails and then sending bogus passwords, 5 times per email per host.


Sorry for late reply. It was 5 attempts per hour per ip. Not per email.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: