Hacker, Hack Thyself
By Jeff Atwood
June 2, 2017 at 04:11AM
via Coding Horror http://ift.tt/2svVFqR
But if 8ms is good, why not 80? or 800? Certainly you could delay authentication by a second without significantly impacting a real user, but foiling attacks by an order of magnitude, at least.