Earlier quoted context omitted.
> A visitor from TOR is extraordinarily more likely to be abusive. It makes total sense to put up extra barriers, which is still short of blocking TOR users altogether, which is also fair for webmasters who don't want to deal with it. And why is that again? I want to understand that argument. In case of DDoS scenario: Well, too late, traffic already served and server already done the workload. In case of password bru…
What about the case of someone signing up for thousands of accounts?
My question is related to the specific /login page, not the registration page.
I understand the benefit for blocking spammer signups, but not for the current case of the login page where users have an account already, were verified that the account/password was correct (captcha appears in second step), and then have to enter a second decryption password manually.
In that scenario there's no argument on the "WHY" a captcha helps. It simply doesn't.