Hacker News new | ask | show | jobs
by gfxmonk 4587 days ago
If they rate limited per user, you could trivially prevent someone from logging in by pummeling the server with login attempts for their username.
1 comments

If there are limits per-user and per-IP, they would need a shit ton of IPs to do that to any reasonable number of users.