1) google recaptcha on login 2) on multiple login attempt disable account for 1 day 3) make sure one user can't access other user data