As we all know there was a recent vulnerability on Facebook that was exploited by an Indian developer as stated here.
Brute force in 2016 is very weird, Facebook applies rate limiting while entering the code for phone , Why they are not using CAPTCHAS ?
Isn't the problem be avoided by adding captcha ?
Thanks