Captcha on the non-changeable eSpaces
715
Views
1
Comments
On our RadarOn our Radar
Frontend (App Interfaces)
Like Users and ServiceCenter. Make a captcha appear after a number of failed tries by user account, not by ip nor session.

This has been flagged as a risk in our security testing. Obviously, developers could enhance the base Users module to use CAPTCHAs, but then you have to worry about upgrades. CAPTCHAs should be a core feature.