Hacker News new | ask | show | jobs
by giltotherescue 5532 days ago
Another method is to pause for an exponential delay after each failed attempt. This makes it prohibitively slow to brute force.
1 comments

The benefit of the captcha method is that your account can't be DOSed -- the legitimate user can still get in by entering one captcha, which is much better than, say, having to wait for an hour.