Is server hardware vastly more powerful? If you use a hashing algorithm that isn't easily parallel, then you're dedicating a single CPU core for that exercise. Now a server may have more cores, but they are often slower per-core than a client machine. And dedicating server resources has a cost. You'd slow a brute force attack to a relative crawl, especially if the target has a large volume of pre-defined work and answers.
PBKDF2, as an example on 100k iterations can easily pin a CPU core for a few seconds. This is part of why I always have my authentication services separate from my applications, it reduces the DDoS vector. Now, you can shift work to the client as kind of an inverse-ddos rate limiter.
Combine that with a websocket connection, where the browser is sending user events like mouse movement, touch, scroll, focus/blur and input/paste... the two, combined with event timing analysis can give you a pretty good guess if something is a real user. And if it isn't, definitely slowing down bots.