This only prevents brute-force password guessing, it doesn't solve the problem of the timing attack. Especially on passwords, which don't change very often. A patient attacker would try only a few attempts at a time, get timing info, then wait out the cooling period until the penalty is back down to 1 second of sleep, then repeat. Each time they gain more information which can all be put together to complete the attack.