I manage a website which uses Firebase Authentication with email and password to login.
I want to do some brute force attack protection. However it is not important for me which exact mechanism is used. However it's important that is it easy to implement and maintain. Also our users are not especially tech savy, so I am trying to avoid 2FA.
It could for example be a mechanism which forced the user to verify their email after three failed login attempts.
Therefore I was hoping to find some help in the docs. However I could not find any easy to use built in mechanism. Most answers mention that you could contact support if you see mysterious traffic. There is also specific advise for specific kinds of attacks.
Can anybody provide an example to a simple, effective, and easy to implement mechanism guarding against brute force attacks?