4 ms·
captchas really aren't particularly suited to the task. The difference between even the most forgetful user and the lowest key bruteforce is so many orders of m
by trotsky 16y ago
captchas really aren't particularly suited to the task. The difference between even the most forgetful user and the lowest key bruteforce is so many orders of magnitude that it should be trivial to detect. I have no idea what facebook does, but most services just make it too slow to be practical: progressively slower responses, rate limiting, lockout periods. Another approach is to fail all authentications over a rate limit so that even if the correct password is guessed the attacker doesn't know. Long story short is defending a service against brute forcing is generally pretty easy.