Hi Tom,
HTProtect is designed to have full and exclusive control over the .htaccess file. You’re not supposed to make manual changes to it (hence chmod 444).
If you want Brute Force Stop to be written in, you can flip the last switch in the advanced shield settings - "manage .htaccess externally" - then HTProtect won’t touch the .htaccess anymore.
Personally, I’m not a big fan of IP blocking against brute force on the Joomla side. Usually, hosting/server-side protections (like Fail2Ban) are already in place, and blocking constantly changing IPs only helps so much. Long, complex passwords make way more sense.