Make sure you get a prog or script that recognizes multiple IP's for the same login, and after 2-3 lock them out, change their password, and be done with it.
When someone tried this shit, I get an instant e-mail as soon as a 2nd IP pops up for same username, and server or prog automatically changes password. If it happens again, they are locked out, and have to contact customer support. If they try and do a chargeback (yes, it happens), they are banned from all sites via IP.
Not too hard to protect yourself. Always better to have in place, then have someone get in and d/l your entire site or whatever.
