Comment 7 for bug 1688137

Revision history for this message
Lance Bragstad (lbragstad) wrote : Re: Attacker may use PCI-DSS 8.1.6 and 8.1.7 to lock out users indefinitely

@Sam, correct. Expecting deployments to have that service would be unrealistic. It would be a work around for a deployment susceptible to the issues and want to mitigate out-of-band.

I'd be interested in investigating Morgan's proposal further.