> Heh, after an independent security review we are being forced to take this even further; We lock people out for five minutes after three invalid login attempts. We are no longer allowed to tell users they have been locked out. So, even if they do remember their password (or even does a reset) we just have to tell them their uid/pwd is wrong when they try to log in. And for “forgot password”? Just tell the user “we have sent you an email – IF we recognised the email you put in”.
This sounds absolutely horrible, and now I'm wondering if I've been subject to this behaviour. Couldn't remember my password (for a trivial site where I use one of my reuse passwords and didn't put it in KeePass), started doubting if I had the correct email, eventually reset the whole thing, reset the password to the password that I thought it should have been, and got an error telling me the new password couldn't be the same as the old one.