Hacker News new | ask | show | jobs
by squeaky-clean 1710 days ago
I'm no security expert, but this would let someone try two unrelated passwords at once and so probably wouldn't be done client-side.
2 comments

In practice is there really any difference between allowing a client to try 10 passwords before 'lock out' (say no more attempts for 10 minutes), or try 5 passwords before hand.
Ouch, you are right.