FAQ SOP: What lockout numbers should I set for failed logins?
Vague "a few tries" is not a policy. Use concrete thresholds.
— Failed attempts before lockout: 5.
— Lockout duration: 20 minutes on first trip.
— Repeat offender (3 lockouts): extend to 24 hours.
— Lock by IP and by username, so distributed attacks still count.
— Notify admin after 10 lockouts in an hour — that signals a real campaign.
— Verify: deliberately fail 5 times and confirm you are locked.
— Verify: lockout log records IP, username, and timestamp.
Too strict locks out real users; too loose invites brute-force. 5/20min is the proven balance.
Run this on every site with a login.
Lockdown Ledger
@LockdownLedger
FAQ SOP: What lockout numbers should I set for failed logins?
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.