4 ms·Yes you still need recaptcha simply to avoid password stuffing attacks.by theappsecguy 1y agoYes you still need recaptcha simply to avoid password stuffing attacks.damsalor 1y agoCertainly not in the mentioned 2fa scenario. I would guess that simple rate limiting would do the trick for the restZak 1y agoRate limiting does not solve this problem because botnets often don't make repeated requests from the same IP address. 2FA does solve it.