Suggestion: Block IP for webserver access after X unsuccesful tries
Comments
-
SecuritySpy already detects this situation and delays its responses after several failed login attempts. This limits the frequency at which an attacker can attempt to brute-force the password, making it virtually impossible to guess a strong password. So I think the current protection is strong, though perhaps an additional automatic temporary block, in addition to the delay, would be a good idea - we'll see what we can do for the next update.
