Our default captcha is pretty terrible, and besides, even something like recaptcha is pretty easy to defeat these days. The main issue is that captcha is bad for accessibility.
We already have honeypot, throttling, and email validation to prevent spamming on the registration page. At the very least, we should make the captcha disabled by default in the configuration settings.
Our default captcha is pretty terrible, and besides, even something like recaptcha is pretty easy to defeat these days. The main issue is that captcha is bad for accessibility.
We already have honeypot, throttling, and email validation to prevent spamming on the registration page. At the very least, we should make the captcha disabled by default in the configuration settings.