The brute force log-in attempts continue. Lockouts didn’t really help because they’re apparently using a wide selection of IP addresses. I didn’t want to do this, but I’ve added a CAPTCHA to the log-in page. Hopefully it won’t be too annoying. Once again, let me know if there are any problems.
As a “spoonful of sugar” I’ve given it a humorous and relevant word list. For example the CAPTCHA might be “naked boobs”. Obviously this isn’t terribly secure, but I can’t imagine this is more than a low-effort attack of opportunity, so hopefully that’ll be enough.