That defeats the brute-force attack protection…
The idea is that brute-force attackers will only check each password once, while real users will likely assume they mistyped and retype the same password.
The code isn’t complete, and has nothing to do with actually incorrect passwords.
I don’t know how to feel about this. On the one hand, this seems like a clear violation of personal rights. On the other hand, without some sort of detainment mechanism, I don’t see how any program would help drug addicts who aren’t interested in recovery.