Defences
- Rate limiting — block after N failed attempts per interval
- CAPTCHA — prove the request is from a human, not a bot
- Account lockout — temporary lock after X failed attempts
- 2FA — even with a compromised password, a second factor is required
- Bcrypt/Argon2 — slow hashing that makes hash enumeration expensive
Dictionary attack
A brute-force variant — trying a dictionary of common passwords rather than all combinations. "password123" and "qwerty" are tried first. Passwords must therefore be long and random.