Hacker News new | ask | show | jobs
by im3w1l 4091 days ago
A site I know allows 5 login attempts per hour. That seems plenty for legitimate purposes. I've never heard anyone complain.
1 comments

But it doesn't matter if they keep hitting their service with a list of known emails and then sending bogus passwords, 5 times per email per host.
Sorry for late reply. It was 5 attempts per hour per ip. Not per email.