Captcha in private mode

easyit December 23, 2020

Hey,

why is the Captcha only for Public mode?

Our users need more comfort.

So I dont want to use Fail2Ban or 2FA.

At first a Captcha would be fine to fight against brute force attacks.
(Please let us not discuss what is more secure).

Basic question: Why is the Captcha only for Public mode? 

Cheers

1 answer

1 accepted

0 votes
Answer accepted
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 23, 2020

It's not.

Captcha is used in two places.:

If someone is signing up for a new account, in Public mode, Captcha is recommended to try to stop 'bots firing up malicious accounts.  You don't need it in private mode - your admins have to add people, and we generally have to assume that your admins know who they're adding and have already decided that they are humans.

If someone gets their password wrong too many times, they will be asked for a Captcha after a handful of wrongs.  The mode does not matter

Nathan G
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 6, 2021

Unfortunately, when you enable captcha for incorrect password attempts via "Maximum Authentication Attempts Allowed" setting. It opens Jira up for User Enumeration, as the captcha ONLY displays when invalid passwords occur for VALID users.
If you try to log in with an invalid user, the captcha never shows up.

Atlassian doesn't appear to care about this little bug.

Suggest an answer

Log in or Sign up to answer