Hi All, 

After carefully reading all the issue, here is my opinion. 

I don't think it's the scope of trytond to fight against DDoS attack, so for me no issue at all. I want to propose Reverse nginx proxy [1] as another option to fight against DDoS attacks.

About the proposed patch it does not solve the DDoS attack, as it give an easier way to brute force some user password (explained on msg24650), which will ease the attacker the possibility to obtain a valid user/password. Once the user has the valid user/password, it can consume the host resources quicklier, for example by creating invoices and this will colapse the system easier. 

