Understanding Account Login Security with Captcha

Created by Surya Boddu, Modified on Tue, 2 Apr, 2024 at 9:21 AM by Surya Boddu

1.0 Overview

For any Seller, there will be multiple staff members with access to their business operations. It is no different when it comes to their Bitsila Account. The seller account can be accessed by all the staff members registered under the account. Even with the limits placed on their account and data access based on their roles and responsibilities, they can still access a lot of information about the business through their accounts with a simple login process.

So, it is essential to ensure that the login process is secure for the safety of the data and business information.

For that reason, we implemented a few security measures and captcha verification for any suspicious attempts of log in.

2. Login Process

Before we go deeper, let’s take a brief look at the login process.

Every user will have their own unique login credentials, which are their mobile number and their own password.

In the login interface, they need to use these login credentials to login.

Up on Successful login, they should be able to access the account interface.

If the user enters a wrong password, however, an error message will be triggered and they cannot access the interface.


3. Capturing Failed Login Attempts

When a user enters a wrong password, an event will be triggered on the system side to record the failed attempt to login.

To access this, go to the Admin Module on the System side and click on Login Failed Attempts.

You can see the failed login attempts in the tabular format.

4. Captcha Trigger

When the login attempts of an account fail more than three times in a row, the captcha process will be triggered.

Now users have to enter the proper credentials along with the captcha to login to the account.

5. Account Deactivation

If the account login fails for 10 times because of the wrong password, the account will be deactivated and even if the correct password was used afterward, the user cannot access the account.


6. FAQs


Q1: Why is login security important for Bitsila Accounts?


A1: Login security is crucial to protect sensitive business information from unauthorized access. Multiple staff members have access to seller accounts, making it essential to secure login processes for the safety of data and business operations.


Q2: What are the login credentials for Bitsila Accounts?


A2: Every user has unique login credentials, consisting of their mobile number and a password. These credentials are required to access the Bitsila Account interface.


Q3: What happens in case of a wrong password entry during login?


A3: If a user enters an incorrect password, an error message will be triggered, preventing access to the account interface. The system also records failed login attempts, which can be viewed in the Admin Module under "Login Failed Attempts."


Q4: How does the captcha process work for failed login attempts?


A4: If there are more than three consecutive failed login attempts, the captcha process is triggered. Users must enter the correct credentials along with the captcha to successfully log in and access their Bitsila Account.


Q5: What is the purpose of capturing failed login attempts in the Admin Module?


A5: The Admin Module captures and displays failed login attempts in a tabular format. This feature helps monitor and identify any suspicious login activities, enhancing the overall security of the account.


Q6: What happens if there are repeated failed login attempts?


A6: If an account experiences 10 consecutive failed login attempts due to incorrect passwords, the account will be deactivated. Even if the correct password is used later, the user will be unable to access the account. This measure is in place to prevent unauthorized access and ensure account security.


Q7: Can a deactivated account be reactivated?


A7: Currently, there is no automatic reactivation process for a deactivated account. Users are advised to contact Bitsila support for assistance in reactivating their account after it has been deactivated due to repeated failed login attempts.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article