|
|
|
|
|
by Dalewyn
707 days ago
|
|
>lock out users after X attempts Legitimate users usually aren't going to fail more than a couple times. If someone (or something) is repeatedly failing, lock that shit down so a sysadmin can take a look at leisure. >disallow users to choose a password they used previously (never understood that one) It's so potentially compromised passwords from before don't come back into cycle now. |
|
There's so many reasons I get passwords wrong. (it doesn't help that work has 4 systems that all use different passwords, all with different requirements).
If you locked me out (without me being able to easily unlock myself), I would immediately consider this an even-more-hostile relationship than normal and would immediately respond in kind.