As recommended by Fable 5 security review. We already have the captcha but it would make sense to have a per account cooldown period for failed logins.
It also suggested IP based rate limits and timeouts but I think we should only add them to defend against a specific ongoing attack if it happens
As recommended by Fable 5 security review. We already have the captcha but it would make sense to have a per account cooldown period for failed logins.
It also suggested IP based rate limits and timeouts but I think we should only add them to defend against a specific ongoing attack if it happens