Is it immoral to put a captcha on a login form?

前端 未结 6 1678
执念已碎
执念已碎 2021-02-05 08:10

In a recent project I put a captcha test on a login form, in order to stop possible brute force attacks.

The immediate reaction of other coworkers was a request to remov

6条回答
  •  半阙折子戏
    2021-02-05 08:17

    It's not immoral per se. It's bad usability.

    Consider security implications: the users will consider logging in to be time consuming and will:

    • be less likely to use your system at all
    • never log out of your system and leave open sessions unattended.

    Consider other forms of brute-force attack detection and prevention.

提交回复
热议问题