> The only problem is that you force legitimate users to wait as well.
I think that's what he meant when he said "realistically". In the reply I posted the quoted text points out that for busy auth servers, it increases potential for DoS.
I think that's what he meant when he said "realistically". In the reply I posted the quoted text points out that for busy auth servers, it increases potential for DoS.