OP 15 February, 2020 - 08:02 AM
Bcrypt uses a ton of resources. UCP > Password doesn't have a captcha setup at all. You could potentially just spam password request changes with random strings as the password and the server would check every request. Enough requests = oh shit. Not to mention the fact it only takes like 6 lines of code in JS to make a tool for it.