But stop making me click the friggin’ stop lights every time I log in to my own account.
rate limit
> stop bots from submitting fake data to sign up forms
I don't think there's an universal solution here. it depends on the application itself and why you consider fake signups an issue in the first place.
add an email-reset for the limit so users can't be locked out of their accounts by a DoS.
To stop fake signups, require confirming the email address and only allow some number of signups per IP per day. It's not perfect but neither are CAPTCHAs and either way you can probably stop most spam, if it's even a problem for you.
I imagine using a standard text field and then hiding it using css probably works much better than setting a type=“hidden” field. I also usually use something like name=“phone” and then just naming the actual phone field something else, if needed.
Generating simple math question/answer can work well enough to keep out non-targeted traffic (someone not targeting a bot tailored to your site).
If you want to hinder determined (but inept) adversary, impose reverse time limit: make your captcha a bit complex and deny answers, that arrive too fast. Legit users will spend a bit of time to solve captcha. Machine-learning-driven bots will blaze it. In addition to measuring speed of filling captchas you can measure amount of user time spent on other actions on your site — in process making your bot detector increasingly similar to Google's reCAPTCHA.
In general look for behaviors, distinguishing legitimate users from malicious. Hint: having Google account might or might not indicate a legitimate user, but it is probably more efficient to ask users for it directly than in roundabout way by using reCAPTCHA.