Block a user
Add id to user table and use as primary key, keep username unique
Cancel/timeout tracker-request after 3-5s (instead of 15s) and retry once before failing
Info-Button and/or manual/usage-tips
Limit password field to 72 characters