The best and most user-friendly way to do this is to let the user know that they have entered incorrect information. A better way is to implement 2FA which will help with brute forcing. Even better way is not to have authenticated=true in the system. I was able to hack that in 2 seconds, even...