logoalt Hacker News

mehovyesterday at 9:40 PM1 replyview on HN

> because we want to keep free and logged-out access

But don't you run these checks on logged-in users too?


Replies

MyNameIsNickTyesterday at 9:48 PM

Yep, on logged-in users too. The reason is basically the same: we want scarce compute going to real people, not attackers. Being logged in is one useful signal, but it doesn’t fully prevent automation, account abuse, or other malicious traffic, so we apply protections in both cases.

show 4 replies