Fedora's invisible passwords and visible squabbles
Fedora's invisible passwords and visible squabbles
Posted May 9, 2013 16:09 UTC (Thu) by andresfreund (subscriber, #69562)In reply to: Fedora's invisible passwords and visible squabbles by mitr
Parent article: Fedora's invisible passwords and visible squabbles
> I think it's exactly the other way around: systems should lock users out, at least for some time, on incorrect attempts; if they do, the passwords can be much shorter and easier to enter.
> This is especially applicable to web applications, where every log in attempt is "online" and the lockout policy can be consistently enforced.
Making it extremely easy to lock somebody out of their account. Pissed about somebody? Enter 10 times the wrong password on their email account's web interface. In contrast to protecting my account with a good password I can't do anything to protect my account to being temporarily blocked in this case.
