server
server copied to clipboard
Incorporate ideas from OWASP's Authentication Cheat Sheet
I think most importantly, authentication errors should be generic. Also, usernames could be made case-insensitive.