When checking for previous invalid login attempts we should hash and salt requesting address so it doesn't disclose user's personal IP address.