That's actually not always enough. For example, to fix this login CSRF on HN, you need a per-visitor secret an attacker can't read (like a cookie) plus a form value based on that secret. Note it can't be tied to the user account, because the visitor hasn't logged in yet.
A random CSRF token on a login form is easily defeated - the attacker just requests a valid one and uses it when submitting the CSRF form.