Request For Comment: Possible Flaw of Bypassing CAPTCHA in AWS Login?

Posted by David Leo on Apr 26

The process of AWS login has a feature: if you use “fresh” browser(no cookie, no cache, etc) to sign in, put correct
email and correct password there, CAPTCHA is required(“To better protect your account, please re-enter your password
and then enter the characters as they are shown in the image below”).

And I accidentally noticed this feature can be easily bypassed:

MY SYSTEM
Knoppix 7.6.0 on Read-Only USB Stick – always…