If you don't log in, every time you want to download a file you are forced to fill out a captcha. If you are logged in, you still have to fill in a captcha, however not as often. My petition is to instead use Google's invisible reCAPTCHA, which can be programmed to automatically check using Google's system by simply clicking on any button. This will reduce the annoyances of a traditional captcha, and make it better for users.
I'd love to, however, it doesn't provide any decent protection against targeted attacks, when the system can be solved for pennies on the dollar. Attacks we have received here have shown that Google's CAPTCHA solution is not a feasible fix for a well-funded adversary.
Our own solution on the other hand, takes some custom code for a would-be attacker or spammer to abuse, and they are generally intelligent enough to use tools, but not intelligent enough to employ a bespoke solution.
We m