Comment Re:Rethinking our approach (Score 0) 99
> Throttling is ineffective if you base it on IP address...
I didn't dictate any specific throttling algorithm. You are stabbing a strawman.
> an attacker obtaining the encrypted vault is probably not going to be able to decrypt many passwords,
That may not be how they breach them. It's an extra layer or device that may have an inadvertent security flaw. The more turtles in the stack, there more turtles there are to hack.