Aktive Verteidigung gegen Missbrauch — Captcha, Honeypot, Rate-Limits, KI-Budget.
Proof-of-work captcha (ALTCHA) on auth flows.
Hidden field "bookmark" on the feedback form (2000ms minimum fill time).
Per-IP and per-email limits. Per-email: 5/1 h.
Daily token cap of 100,000 per user.
Geht dieses Pattern noch besser? Sag uns, wie.