have you considered
implementing Multi-Factor Authentication
which is considered the most effective defense
because even if attacker successfully
guesses a password, it cannot gain
access without a second verification
factor like a mobile app code,
biometric scan, or hardware token ?
have you condidered to change
login password more demanding
(longer requiring more vsriation...)?
have you checked opalstack.com
login software -
now the only web site where
I can not login
is yours - all
other web sites using this same
CAPTAH accept my login
for example
https://store.steampowered.com/login/
Please, let us know your decisions
and implementation schedule asap
because I can not anymore able to
login to manager our company
assets which our directors regard
as the ultimate nightmare situation
and naturally as admin "my ass" is
in deep trouble!