added rate limiting on our login endpoint after seeing weird traffic patterns. next day we got hit with a brute force attempt and it just bounced off. felt good man