Not too much rationale is needed to motivate brute force profiting for the client area.
However making use of reCAPTCHA is an issue for GDPR & similar policies therefore not an alternative. Everyone uses it isn't really a motivating factor to handle PII on behalf of Google.
Personally a 15 minute ban after X attempts & a 1 day ban after X more would suffice along with a IP looked for unbanning "honest" bans.
Post the first comment
Login to post a comment.