I'll change a members password twice, the 3rd time I cancel the members account and change the pw again, this time I wait for them to contact me. If they do, I'll activate it back, but if it leaks again, I ban the IP for 90 days.
I also scan for leaks in strongbox, to kill the micro leaks that are too slow to set off strongbox. When I find these, I only reset the pw once... after that I start the cancel process as most of these... are bot IP's.
|