Is it immoral to put a captcha on a login form?

前端 未结 6 1680
执念已碎
执念已碎 2021-02-05 08:10

In a recent project I put a captcha test on a login form, in order to stop possible brute force attacks.

The immediate reaction of other coworkers was a request to remov

6条回答
  •  醉话见心
    2021-02-05 08:44

    Captcha isn't a very traditional choice in login forms. The traditional protection against brute force attacks seems to be account locking. As you said, it has it's drawbacks, for example, if your application is vulnerable to account enumeration, then an attacker could easily perform a denial of service attack.

提交回复
热议问题