iofhua: This is absurd. Really? Is this really necessary? If someone wants to automate logging into GOG with a bot, why not just let them? What harm does it do? Are you afraid of making it too easy for someone to buy something?
Whoever came up with this should be smacked across the head. Severely. Several times.
Faenrir: This isn't absurd at all. It's probably necessary, yes. Someone wants to hack through accounts with bots, rather than automate logging in. Brute force is stupid but given enough time, it works. With a captcha, it's harder to manage (still doable though but not worth the time).
No, brute force is useless with encrypted password, something that even yahoo has now learned
Also it nonsense for the first login, it
may have sense for multiple attempts, but it's useless for the first try
Have you ever wondered why no service, like google for example, use such thing? Why no secure server use the triple damned captcha for their unique ID login?
Simple, because it's pointless. Repeated attempt are much more efficiently blocked in other ways, among others temporarily disabling an account, blocking the attempting IP, encrypting the password or using the simple T
wo Step Authentication already available even here
The last solution is simple and effective. If you really want more security, either issue certificates for logging in, or if you really, really have no better idea then using captcha, at least make so it trigger only after 2nd or 3rd attempt. After all it the hacker match the password on the first try, either he should try the lottery instead, or it already have the password, witch make pretty much anything else then the Two Step Login or certificate, useless
To add some flavor to the story, depending on what ISP you have, google captcha may automatically fail for you as all your attempt may be marked as spam, this happen because google detect repeated attempt from the same exit IP point, where other thousand of people get their connection exit point as well
I had that exact problem for example, and could not access my gog account for more then 4 days, after more then
30 attempts, without using TOR, where the triple damned captcha actually worked. Simply unacceptable