Well if a member knows how many attempts they have to attempt someone's password they can brute force an account easier. So you're told "You have 2 more attempts, 1 more attempts 0 attempts for 15 minutes" etc then the person KNOWS that any attempt that they are doing while the account is locked isn't going to work so there isn't a point in trying. If they don't then they could still be trying, get it right ans STILL not get logged in and not know that they got it right.
I hope that makes sense because it makes sense in my head but trying to explain it is a little more difficult.