← Back to context Comment by 1718627440 6 months ago > There's no reason for itThe reason is to add a delay when bruteforcing passwords. 2 comments 1718627440 Reply hananova 6 months ago Bruteforcing is only really done with the password hashes in hand. Attacks on live systems are done with credential stuffing. timhh 6 months ago Definitely not for local password authentication, and I'm dubious it helps for ssh either. See my other comment.
hananova 6 months ago Bruteforcing is only really done with the password hashes in hand. Attacks on live systems are done with credential stuffing.
timhh 6 months ago Definitely not for local password authentication, and I'm dubious it helps for ssh either. See my other comment.
Bruteforcing is only really done with the password hashes in hand. Attacks on live systems are done with credential stuffing.
Definitely not for local password authentication, and I'm dubious it helps for ssh either. See my other comment.