Quantcast
Channel: WordPress.org Forums » [Wordfence Security - Firewall, Malware Scan, and Login Security] Support
Viewing all articles
Browse latest Browse all 33066

Storyman on "[Plugin: Wordfence Security] Block IPs of all 'admin' logins"

$
0
0

Are you saying that content writers have admin rights? Anyone with admin rights should be aware of any restrictions from typing an incorrect username/password combination.

The fact is, locking out someone for ONE instance of mistyped username, which is what WordFence's current options do, is simply bad design.

At the risk of sounding 'hostile' why don't you back off the "one attempt and you're locked out" mentality? Be kinder, gentler and give them at least three attempts to login before locking them out. It is a fair compromise from the all or nothing stance.

If you examine the Wordfence logs you'll discover that nearly all of the hack login attempts are from bots. At first they use 'admin', but over time they try different user names--most of which are variations of poster's names. To add all the variations of usernames used by hacker bots to a blacklist will be an endless task and one that I'm not convinced worth the time and energy. Rather than being defensive and saying anyone who doesn't agree with you is hostile and lacks imagination think through the consequences of what you are asking for. You'd be surprised at the number of people who started with your assumption and after careful consideration found it unmanageable. I could be wrong and would be swayed by a cogent analysis.


Viewing all articles
Browse latest Browse all 33066

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>