We should investigate:
a) Using dns spamblacklists to avoid spam
b) Re-audit all of our rate limits (e.g. for edits), including CIDR policy
c) Only show captchas after IPs show certain amounts of activity
d) Exclude "trusted" users (algorithmically) from captchas
e) Likewise for abusefilter
f) Make good use of Extension:AntiBot
Also see https://www.mediawiki.org/wiki/Extension:ConfirmEdit/FancyCaptcha_experiments