Hacker News new | ask | show | jobs
by Polyisoprene 2540 days ago
Or getting your account banned after someone failed trying to brute force it and not being able to access it due to changes in security policies.
1 comments

Fail2ban bans an IP address or range of IPs, not specific users.
That advice is pretty antiquated.

The reality is that, these days, I rent $5 worth of botnet time and make {user,password} combo login attempts from thousands of residential IP addresses.

You might think your advice is a good "might as well" elementary, but generally if people want to curl your /login page from their laptop, then they are also buying $5 scripts off Hack-Forums that automate botnet cred stuffing against your service as well. And you'll need a better gameplan than fail2ban.