Different scripts/programs work differently. The main idea is to suspend/block an account as soon as you detect it has been shared.
PassGuardian suspends the account first for a few hours and warns the user, then it blocks the account for 24 hours and if it keeps getting accessed by different users it simply blocks it for 7 days/indefinetely. Not like P....... that re-enables blocked accounts after 24 hours. That's just a joke.
We haven't had any legitimate users complaining about a blocked account, simply because PassGuardian bounces every dictionary attack and the users that have shared their password, know they did wrong and don't dare complain.
I doubt though xfalmp, that its the script that requires the 4 digits. This is probably the webmaster that has access to the customers payment info and does a manual check and issues a new username/password.
|