<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[hCaptcha on Login Forms]]></title><description><![CDATA[<p dir="auto">Putting it out there the possibility of Google ReCaptcha or hCaptcha to prevent bots brute forcing login forms.</p>
]]></description><link>https://forum.cloudron.io/topic/5136/hcaptcha-on-login-forms</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 00:35:05 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/5136.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 27 May 2021 05:10:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to hCaptcha on Login Forms on Fri, 28 May 2021 10:41:35 GMT]]></title><description><![CDATA[<p dir="auto">I think enabling 2fa on your Cloudron will prevent brute-forcing already and the validation REST call on the server is pretty light-weight, so I don't think adding a captcha will be of great benefit.</p>
]]></description><link>https://forum.cloudron.io/post/32067</link><guid isPermaLink="true">https://forum.cloudron.io/post/32067</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Fri, 28 May 2021 10:41:35 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 22:49:12 GMT]]></title><description><![CDATA[<p dir="auto">Complete thread hijacking - but if you want to see if your users are password numpties, stick their email address into here: <a href="https://haveibeenpwned.com" target="_blank" rel="noopener noreferrer nofollow ugc">https://haveibeenpwned.com</a></p>
<p dir="auto">Also interesting to see the sort of interests people have from the leaked websites they've sign up to!</p>
]]></description><link>https://forum.cloudron.io/post/32042</link><guid isPermaLink="true">https://forum.cloudron.io/post/32042</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Thu, 27 May 2021 22:49:12 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 22:33:01 GMT]]></title><description><![CDATA[<p dir="auto">I hate captchas - although it is perhaps fair game to add one after a number of failed attempts.</p>
<p dir="auto">As long as there's a minimum password length policy and 2FA enforceable, the rest doesn't keep me awake at night.</p>
]]></description><link>https://forum.cloudron.io/post/32039</link><guid isPermaLink="true">https://forum.cloudron.io/post/32039</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Thu, 27 May 2021 22:33:01 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 22:32:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/d19dotca" aria-label="Profile: d19dotca">@<bdi>d19dotca</bdi></a> All GREAT suggestions.</p>
]]></description><link>https://forum.cloudron.io/post/32038</link><guid isPermaLink="true">https://forum.cloudron.io/post/32038</guid><dc:creator><![CDATA[dylightful]]></dc:creator><pubDate>Thu, 27 May 2021 22:32:20 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 22:31:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> It covers it to a degree. Adding a hCaptcha to the login form kills 95% of bots from submitting the form, thus not sending a full authentication request.</p>
]]></description><link>https://forum.cloudron.io/post/32037</link><guid isPermaLink="true">https://forum.cloudron.io/post/32037</guid><dc:creator><![CDATA[dylightful]]></dc:creator><pubDate>Thu, 27 May 2021 22:31:48 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 17:29:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dylightful" aria-label="Profile: dylightful">@<bdi>dylightful</bdi></a> I think it's a nice idea to add reCAPTCHA / hCaptcha as needed to the page. With that said, as <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> stated, fail2ban should more or less prevent any brute force attacks. Also the Cloudron has rate limits in place by default (<a href="https://docs.cloudron.io/security/#rate-limits" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/security/#rate-limits</a>) for Cloudron login page. Of course, that can be greatly improved as 10 requests per second per IP is far too high in my opinion, should be more like 10 requests per 5 or 10 minutes or something like that. But that was also requested already too to improve the rate limits to be more secure: <a href="https://forum.cloudron.io/post/28271">https://forum.cloudron.io/post/28271</a> which <a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> has <a href="https://forum.cloudron.io/post/28369">already confirmed is going to be one of the focuses in 6.3</a>.</p>
]]></description><link>https://forum.cloudron.io/post/32011</link><guid isPermaLink="true">https://forum.cloudron.io/post/32011</guid><dc:creator><![CDATA[d19dotca]]></dc:creator><pubDate>Thu, 27 May 2021 17:29:16 GMT</pubDate></item><item><title><![CDATA[Reply to hCaptcha on Login Forms on Thu, 27 May 2021 10:08:01 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dylightful" aria-label="Profile: dylightful">@<bdi>dylightful</bdi></a> Fail2Ban should already cover this.</p>
]]></description><link>https://forum.cloudron.io/post/32005</link><guid isPermaLink="true">https://forum.cloudron.io/post/32005</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Thu, 27 May 2021 10:08:01 GMT</pubDate></item></channel></rss>