Skip Navigation

How do CAPTCHAs work without giving you a challenge task?

I have noticed that some CAPTCHA pages, like Cloudflare's, simply ask you to check a box to proceed. There is no clicking on traffic lights or entering characters. How does clicking on a check box tell them I am not a robot?

42 comments
  • Its not sure how it exactly works, but most probably this captcha processes a lot of data like your mouse movement, mouse click but also your browser fingerprints, search history and ip. You can actually get 'traffic lights' test from this clicking button captacha if You have privacy protection in place, such as using brave, tor, firefox or mullvad browser and/or vpn, pluse some privacy browser extensions

  • Slight tangent, but if you want to pass the "click on all the images with traffic lights" first time, select one that's obviously wrong then go back and "change your mind" computers don't do that and 9/10 times it'll pass you first time!

  • How you move or type is one reason. I only ever get challenge things when I am using remote desktop which recently changed how keyboard input is sent. Instead of going each key like it was being typed on the actual machine, it sends a whole line of text at once. Doing this tends to trigger the automation detection and challenges you with the "find all the traffic lights" bullshit.

  • Cloudflare announced their CAPTCHA replacement Turnstile here in 2023

    They don't particularly go into the technical details, but announce:

    We don’t rely on tracking user data, like what other websites someone has visited, to determine if a user is a human or robot. Our business is protecting websites, not selling ads, so operators can deploy Turnstile knowing that their users’ data is safe.

    The tracking reference is about Google captchas using logged-in user account and tracking information to gain confidence in a user being a person and not requiring challenges for them.

    Simple CAPTCHA systems give you a challenge to complete, to show you are human. (As the Cloudflare post points out, it's most of the time easier for bots to solve challenges than it is for humans. But botters still require expertise and solutions.)

    Sophisticated CAPTCHA systems may use any information the web-browser sends them to make a guess on whether the user is human or not, according to probabilistic models. For example the click interaction means you move your cursor, which can be tracked and analyzed against patterns.

42 comments