Comment 2 for bug 138654

Revision history for this message
Kees Cook (kees) wrote :

Since this is a global timeout for PAM, reducing it would change the behavior for network services. However, as you point out, this isn't a very effective way to discourage brute-forcing (especially for network attempts -- it just forks another copy).