Problem Statement
What is a safer alternative to strict account lockout after a few failures?
Explanation
Hard lockouts create easy denial of service. Progressive delays, captchas after risk checks, and alerts make attacks slower while keeping real users able to sign in.
Code Solution
SolutionRead Only
Backoff: 1s, 2s, 4s…; captcha after risk score; notify user on spikes
