Hacker News new | ask | show | jobs
by willxinc 1742 days ago
HSMs typically will have a fixed number of login attempts that reset only on successful login.

If the password verification attempts are passed through directly to the HSM, then yes, this is standard.