Fedora's invisible passwords and visible squabbles
Fedora's invisible passwords and visible squabbles
Posted May 9, 2013 13:27 UTC (Thu) by Funcan (guest, #44209)In reply to: Fedora's invisible passwords and visible squabbles by drag
Parent article: Fedora's invisible passwords and visible squabbles
Locking an account on /enough/ bad passwords makes perfect sense, otherwise dumb brute forcing starts to become too easy - assuming you can extract a list of login names from somewhere, trying a couple of hundred most common passwords on all of them has a good chance of getting a few hits (birthday paradox bites you in the ass).
If you allow complex passwords and have reasonably well educated users, then locking after 10 or 20 wrong attempts, rather than 3, might start to make sense. Locking for a sort time rather than indefinitely might start to make sense too. Fail2ban short term IP blocks might also make sense too
