Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-278

User Login and Throttling Login Errors

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Won't Do
    • Icon: Major Major
    • Recycle Bin
    • None
    • Security
    • None

      We should consider adding behavior that will either throttle a Users Login attempts. Failed login attempts make you wait an x amount of time exponentially before you next login attempt. Example 2, 4, 8, 16, 32, etc...

      Or at least implement a 3 strikes you're out policy until either you're account is re-activated by an admin or a certain amount of time passes.

      Please see the following link for more explanation.
      http://www.codinghorror.com/blog/archives/001206.html

              Unassigned Unassigned
              nhook Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Estimated:
                  Original Estimate - 4 days
                  4d
                  Remaining:
                  Remaining Estimate - 4 days
                  4d
                  Logged:
                  Time Spent - Not Specified
                  Not Specified