Arne Brachhold wrote:
> Viper007Bond wrote:
>> I'm all for blocking people from the login from after X fails, but
>> changing
>> passwords and forcing secure passwords is retarded IMO.
> Definitely. I've never seen a web application / service which changed
> my password without my request.
>> Sure, a strength _indicator_ would be cool, but forcing?
> No, never force it, just mark it as "Bad" so people can decide. Not
> every blog needs a super-secure-10-chacrater password.
> All we need is a solution to slow down automated attacks but without
> annoying the actual user.

Why not add a concept of "safe IPs" or somesuch?  Allow admins to
specify their home IP address (well, assuming they've got a static
one...) as a failsafe IP.  Login attempts coming from anywhere else are
subject to account suspensions, etc., while the home IP is always kept
open as an option of last resort.

I'd just hate to have people DoS'd by jerks attempting to log in, as
previously pointed out, every 19 seconds or so.

