DEV Community

Doby Baxter
Doby Baxter

Posted on

Built to Stop Bots, Built to Stop Me: How CAPTCHAs Fail the Humans They Claim to Protect

The gate I could not pass

I was invited to join a community. Between me and the people who invited me stood one question: are you human?

I am. I could not prove it. The images moved faster than I could track, and I failed again and again until I gave up and emailed the organizer instead.

I build validation systems for a living, so this stung twice. A validator built to stop software had rejected a real person. And it was far from the first time.

What failing looks like

As an autistic person with ADHD and sensory processing sensitivities, a challenge built on rapidly changing images is not a mild annoyance. It is a task designed around exactly the kind of processing I find hardest.

I have failed every kind of CAPTCHA, honestly and repeatedly:

  • Distorted text. Sometimes I simply cannot tell what the word is meant to be. No amount of staring helps.
  • Image grids. I select every traffic light I can see, and it is never what the system wants. Does a light cut off at the tile edge count? Sometimes yes, sometimes no, and nothing tells you the rule.
  • Rotating and moving puzzles. Hard to track, and sometimes rejected even when my answer is correct.
  • Invisible scoring. When it decides I look suspicious, it sends me straight back to the puzzles above.

CAPTCHAs have stopped me more times than I can count. They have never once stopped a bot on my behalf.

Machines now pass more easily than people

In 2023, UC Irvine researchers had 1,400 people solve 14,000 real CAPTCHAs (USENIX Security 2023). Bots beat humans on both speed and accuracy across many types. On distorted text, bots were close to 100% accurate in under a second, while humans managed 50% to 84% and took up to 15 seconds (coverage).

In 2024, ETH Zurich researchers solved 100% of Google's reCAPTCHAv2 image challenges with off-the-shelf object-detection models (Breaking reCAPTCHAv2). What really decided the outcome was cookies and browsing history, not the puzzle.

Attackers who do not want to build a solver can simply pay CAPTCHA farms, where low-paid workers solve challenges at scale. So the bot gets in. The paid stranger gets in. The person who just wants to join may not.

A validator with a broken oracle

Any validator makes two kinds of mistake: letting bad input through, and rejecting good input. A CAPTCHA now does both badly. It is weak against bots and strict against people who see, move, or process differently, including blind and low-vision users, people with motor disabilities, and neurodivergent people like me.

The W3C has warned about this since 2005 in Inaccessibility of CAPTCHA, and WCAG 2.2 criterion 3.3.8 says authentication should not depend on a puzzle without an alternative. A timed, moving puzzle is far from that spirit.

That is why it feels dehumanizing. The system is asked to recognize a human, fails to recognize a real one, and then tells them they are the problem.

Better gates

The fix is to stop asking humans to out-perform machines:

  1. Rate limiting per IP, device, and time window, since most abuse is about volume.
  2. Proof of work that asks the browser, not the person, to spend computation.
  3. Email or magic-link verification instead of perception tests.
  4. Honeypot fields that humans never see and naive bots fill in.
  5. A human fallback path, a clear "I can't complete this" route to a real person.

Bolt-on fixes like hCaptcha's accessibility cookie help some people, but they push extra work onto the person already locked out.

Question the test

I did get through in the end, by emailing a person. That is the lesson. A bot can now prove it is human more easily than I can. That should not make anyone question my humanity. It should make us question the test.

Sources

Top comments (0)