everconfused wrote:
I don't think there's really a good answer to this one. For all it's imperfections, and I know it wasn't perfect, I really wish they'd bring that security code back on the login page. The reason for having that was there are programs (bots?) that will sit and randomly try to "guess" a user password.
They're out in the cold because of a limit on the number of logins you can attempt in a time period. To guess someone's password by trying all combinations would take a relative eternity because of those restrictions.
Trick wrote:
[...]
It's un-crackable
Not really -- it's still vulnerable to a whole host of attacks (cookie grabbers, key loggers and those "verify your bank account" e-mails come to mind).