4 ms·
CAPTCHAs are useful when you want to rate limit something to an extremely low rate, like for example attempting to login with a username and password.
by jeffasinger 11y ago
CAPTCHAs are useful when you want to rate limit something to an extremely low rate, like for example attempting to login with a username and password.
- rnhmjoj 11y agoYou could slow down the responses or rate limit the requests, with no need to completely block automatic logins.
- progval 11y agoYou would have to limit it per IP address if you do not want to after all clients. So it would not be effective against someone who can use many IP addresses (eg. with Tor)
- jeffasinger 11y agoIf you are a valuable enough target, this is not an option. IPs are cheap, if you let someone try 20 times in an hour before banning an IP, there are targets that people will cycle through IPs that quickly for.
- dredmorbius 11y agoTor largely prevents most approaches to this. You'd need some way to provide a ticket to a given client, check for it later, and, preferably, ensure anonymity over time. I've just posted top-level in this thread listing two projects of which I'm aware that provide this, though as experimental protocols only. I've been mildly agitating for further development of such tools. Looks as if CloudFlare are working in a similar direction, which I see as positive.