by m3h·8y ago·view on hn ↗Would requiring clients to hash passwords for a large number of times before sending them help? I imagine a 3s second effort would be unnoticeable by human users but hurt the attack rate? That and maybe block the offending IPs, at least temporarily?