This. Instead of having a timeout after n-number of passwords, have a random timeout after each one (between 1 and 3 seconds). Not really a big deal for a user (you can hold the connection open, so the browser looks like it's waiting for a response, or put up a loading spinner) but makes brute forcing infeasible.