Better to make it deterministic, eg. display a fake success page whenever sha1('salt'+login+password) has two leading zeros.
That way you can easily control the fake success rate, and you make sure that if the attacker realises they are being tricked, they can't just retry successful logins to double check, since they get the same result every time.