Yes that help, I understand your choice. Nevertheless, one more variable related to an additional custom field in order to set the desired number of minute(s)/hour(s)/day(s)/week(s)/month(s) isn’t, in my opinion, hard to deal for the maintenance of the plugin. And the user experience will be improved, imo.
Why am I asking for this? Because in a membership environment, there will be 2 kind of visitors :
1 – legit users which can try to login multiple times because they don’t remember their password (this can happen to everybody)… and that’s why, in this case, you can’t set it to 1 transgression. or if you do so, you have to blacklist him for 1 minute only, which will not fit the need for the 2nd kind of “visitors” : bots
2 – Allright, here we go, with bots trying to bruteforce your login/password. You can set a rule for 5 transgressions (in order to let everybody a chance to fail), but because you take care of brute force attacks, you have then to set it up to a 1 hour blacklist. Allright, but what will happened to the “legit user” then, who failed 5 times because he was just tired of his day work? Shall he wait 1 hour? What a sad life :p
Even if my english isn’t perfect, I hope you understand what I mean : there is a gap too much important for some particular uses. And I really think that being able to choose a number of minutes for the blacklist is the best deal we can have.
Regards.
-
This reply was modified 8 years ago by moxymore.
-
This reply was modified 8 years ago by moxymore.