1 is a very bad idea. Someone can just go through all screen names and script bad logins to lock almost all FR accounts for that 4 day period.
Interesting thought. Maybe not a 24-hour lock, maybe just a 5 minute one. If you have your correct password, a five minute wait isn't too problematic, but it would totally frustrate a brute-force crack attempt.