[citation][nom]memadmax[/nom]There's an easy way to stop list bruteforce tactics: 30 minute timeout with an email enforced password change after 3 failed login attempts... also, forced password change after first time login, with previous passwords cached for non-use later(if the user attempts to use a previous password again, it fails)... These password tactics are very, very, very easy to implement... few lines of code in most cases....[/citation]
Yahoo (or was it another website?) has a 24-hour policy. Fail the passwords three times, and you're done for the day.
The only issue is trolling. If you can get hold of someone's username, then it's very easy to lock them out of the account. :/