Having to solve the Captcha for logging in is bad for usability. You can argue that you can stay logged in to work around this, but that is not really useful. The only benefit appears to block brute force attacks, but to accomplish this you should rather display the captcha when there are e.g. 3 failed login attempts for the user. Here's a tweet (in german), expressing the user experience: http://twitter.com/fst/status/14896996437 More
2010-05-29