<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Adding CAPTCHA to login page</title> 
  <pubDate>Thu, 09 Apr 2026 19:39:44 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/6014</link> 
  <atom:link rel="self" type="application/rss+xml" title="Adding CAPTCHA to login page" href="https://bugs.horde.org/ticket/6014/rss" /> 
  <description>Adding CAPTCHA to login page</description> 
 
   
   
  <item> 
   <title>Hello,



Is there any way to add a CAPTCHA control on the l</title> 
   <description>Hello,



Is there any way to add a CAPTCHA control on the login screen (after login and password) ?



Thanks</description> 
   <pubDate>Sun, 16 Dec 2007 13:29:08 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39965</link> 
  </item> 
   
  <item> 
   <title>No, and it doesn&#039;t make much sense. If you don&#039;t even trust </title> 
   <description>No, and it doesn&#039;t make much sense. If you don&#039;t even trust your authentication backend, why would you trust a CAPTCHA?</description> 
   <pubDate>Sun, 16 Dec 2007 14:05:10 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39968</link> 
  </item> 
   
  <item> 
   <title>&gt; No, and it doesn&#039;t make much sense. If you don&#039;t even trus</title> 
   <description>&gt; No, and it doesn&#039;t make much sense. If you don&#039;t even trust your 

&gt; authentication backend, why would you trust a CAPTCHA?



The question isn&#039;t trusting or not the backend.



Many robots can search to log on Horde. A CAPTCHA solution blocks robot&#039;s query.</description> 
   <pubDate>Sun, 16 Dec 2007 16:57:28 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39969</link> 
  </item> 
   
  <item> 
   <title>&gt; No, and it doesn&#039;t make much sense. If you don&#039;t even trus</title> 
   <description>&gt; No, and it doesn&#039;t make much sense. If you don&#039;t even trust your 

&gt; authentication backend, why would you trust a CAPTCHA?



When I say &quot;after the login and password&quot;, I don&#039;t say that a CAPTCHA must be run after a successfull login. I just say that the field must be placed after the login and password field, but on the same page !</description> 
   <pubDate>Sun, 16 Dec 2007 16:59:21 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39970</link> 
  </item> 
   
  <item> 
   <title>&gt; When I say &quot;after the login and password&quot;, I don&#039;t say tha</title> 
   <description>&gt; When I say &quot;after the login and password&quot;, I don&#039;t say that a CAPTCHA 

&gt; must be run after a successfull login. I just say that the field must 

&gt; be placed after the login and password field, but on the same page !



Your initial request was misleading in this regard, but I still don&#039;t see how this would help you to protect against robots. And against robots doing what exactly?</description> 
   <pubDate>Sun, 16 Dec 2007 17:12:57 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39973</link> 
  </item> 
   
  <item> 
   <title>&gt; Your initial request was misleading in this regard, but I </title> 
   <description>&gt; Your initial request was misleading in this regard, but I still don&#039;t 

&gt; see how this would help you to protect against robots. And against 

&gt; robots doing what exactly?



Example: testing login on Horde by sending different login/password. Of course, the server will reject all bad accounts but this will cause using some resource and can cause an attack like DoS attack (server using too much time processor and other resources to treat requests).</description> 
   <pubDate>Sun, 16 Dec 2007 17:22:39 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39974</link> 
  </item> 
   
  <item> 
   <title>This is something that should be implemented in the authenti</title> 
   <description>This is something that should be implemented in the authentication backend, not in the frontend.</description> 
   <pubDate>Sun, 16 Dec 2007 23:11:15 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39977</link> 
  </item> 
   
  <item> 
   <title>&gt; Example: testing login on Horde by sending different login</title> 
   <description>&gt; Example: testing login on Horde by sending different login/password. 

&gt; Of course, the server will reject all bad accounts but this will 

&gt; cause using some resource and can cause an attack like DoS attack 

&gt; (server using too much time processor and other resources to treat 

&gt; requests).



I agree with Jan, and further, adding a captcha to the equation just adds a _different_ resource to try to DoS.</description> 
   <pubDate>Mon, 17 Dec 2007 03:11:47 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t39983</link> 
  </item> 
   
  <item> 
   <title>If you are concerned about brute force attacks, have your au</title> 
   <description>If you are concerned about brute force attacks, have your authentication backend have long delays on bad authentication requests.  Or require passwords above a certain length.  Combining captcha&#039;s with password is unneeded replication.</description> 
   <pubDate>Fri, 18 Apr 2008 21:27:02 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6014#t44731</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
