DoS left aside, if 50 users per second could (possibly) log in and you do not want to spend big $$$ on load balancing just for logging in, then anything that takes much longer than 10-20 ms is no option, especially since the problem becomes a feedback loop at some point (users that notice that login takes longer than they expect assume that something is wrong, and hit the button again!).