Does facebook use captchas, to slow bruteforcing, I tried entering a few wrong passwords for my account but didn't get one. However I doubt that bruteforcing or a dictionary attack was used.
captchas really aren't particularly suited to the task. The difference between even the most forgetful user and the lowest key bruteforce is so many orders of magnitude that it should be trivial to detect. I have no idea what facebook does, but most services just make it too slow to be practical: progressively slower responses, rate limiting, lockout periods. Another approach is to fail all authentications over a rate limit so that even if the correct password is guessed the attacker doesn't know. Long story short is defending a service against brute forcing is generally pretty easy.
facebook doesn't use captcha's as much as it does other security features. if there is a log-in from an ip address that seems suspicious, it can ask you to identify your friends in photos to verify your identity.
Which is actually so much less annoying than captcha. Seems less secure (probably trivial for people you know to break in) but it's certainly a novel approach.