Why do they not lock the account after n number of tries say 5?
The user will need to use a different way to authenticate if they can't enter the correct code in 5 tries
The user will need to use a different way to authenticate if they can't enter the correct code in 5 tries
[Obvisouly, there are ways just easy to screw up]