CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
CAPTCHAs don't work anymore, at this point. AI can trivially solve them.
Rate-limit the number of attempts, test accounts against known-password lists like HIBP, and support 2FA.
The point is to raise the cost, not to create some impenetrable barrier. A $5 vps can make hundreds of requests per second. IP bans and rate limiting forces people to use residential proxies, which are like $5/GB. That's much more expensive, but still cheap. Not sure about the token cost of AI is like, but captcha solving service used to charge around $0.002 per solve, which increases costs even more.
OS, browser, fingerprinting, networked bytes, residential address spaces.
All of it is done.
If a website/app goes passkey only (or, even worse, if it starts relying only on one-time email codes), I won't use it.
I know plenty of others who feel the same, though I don't know if we're numerous enough to put a dent in a company's bottom line or not. I imagine it depends on the company and its target audience.
Passkeys or magic links seem like the way forward here.
The point is to stop the attack and prevent users from accidentally hosing themselves.
That's basically a passkey without its special API.