If I disallow X requests per second then I might enable DOS attacks on a user.
What if a cluster of zombie machines around the world is attempting to log in as a politician to gmail at their publicly known address? How would the politician ever get in, if login attempts are rate limited?