FlyerTalk Forums - View Single Post - Consolidated "CAPTCHA for logging in?" thread
Old Feb 3, 2015 | 8:52 pm
  #305  
exerda
Moderator, Omni, Omni/PR, Omni/Games, FlyerTalk Posting Legend
20 Countries Visited
1M
40 Nights
20 Years on Site
 
Join Date: Oct 2004
Location: Between DCA and IAD
Programs: UA 1K MM; Hilton Diamond
Posts: 72,452
So why not have accounts temporarily lock after, say, 5 failed login tries, and e-mail the account holder that it appears someone is trying to hack their account?

The only thing the Captcha would defeat is if someone had a massive DB of login & password combos which are "legit" from some compromised site (and not just a brute force dictionary), and are using robots to try those combos at a bunch of common sites to find accounts where the person used the same username & password. I'm assuming that's what is being done, but it still seems like there would be better ways of doing this.

And you could still have humans try those stolen usernames & passwords on a few high-value sites (banks, hotels, airlines, etc.) to bypass the Captcha.
exerda is offline