Fedora's invisible passwords and visible squabbles
Fedora's invisible passwords and visible squabbles
Posted May 9, 2013 15:18 UTC (Thu) by apoelstra (subscriber, #75205)In reply to: Fedora's invisible passwords and visible squabbles by Funcan
Parent article: Fedora's invisible passwords and visible squabbles
> If you allow complex passwords and have reasonably well educated users, then locking after 10 or 20 wrong attempts, rather than 3, might start to make sense. Locking for a sort time rather than indefinitely might start to make sense too. Fail2ban short term IP blocks might also make sense too
If you had said 100 or 200 attempts, I'd agree with you. No human is going to accidentally mess up a password that many times, any bad guy who can guess the password in fewer tries knows too much anyway (you already have compromised security), and brute forcing is completely blocked.
Alternately, blocking unilaterally for 15 or 30 seconds after every bad attempt would also prevent brute-forcing, as well as be extremely irritating to human bad guys.
