Posted November 05, 2015
Zrevnur: @GOG: Please do away with these user harassment practices - ie having to verify that I am human. It may make sense to use such schemes for "repeat offenders" but people who are clearly not fakes (logged in, just spent $$$, have never before failed at inputting a correct code) certainly should not be put through this.
That's not how secure systems work. A secure system always challenges entry and never makes an exception since exceptions are exploitable. If GOG stops challenging all users, then it become much more appealing to compromise established active accounts for illegitimate uses. We already get enough account hijacks these days, GOG does not need to make that a more popular activity by reducing the already limited security they use.