I am wondering what is the best way to handle blocking computers after users have made 5 incorrect login attempts.
I thought this was done by IP, but then I started thinking about whether users are coming through the gateway and sharing a common IP address. I would not want to potentially block users of legitimate users, because someone on the same network is entering incorrect data.
Cookies are another option, but users can clear them from the browser, so I think they would be very inefficient.
Can anyone else give me more ideas on this?
Thanks Mic
source share