There's still the "keep me logged in" function. I'm not a big fan of the "show captcha after failed login" because, in most cases, this is bound to the php session and thus can be bypassed by just ignoring the php session id.
Also we're using nocaptcha recaptcha, thus, in most of the cases, you'll just have to click it.