Anyone who enabled two factor authentication has it worse. Not only do you need to successfuly manage to not timeout after you password. You have 30 seconds to put in your authenticator code and pass another timeout check. People can not even login to the website to turn off the authenticator because too many failed attempts logs you perminenetly for 30 minutes. And a Timeout counts as a failed attempt.