3 4 5 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

What is Captcha

CAPTCHADefinition:

A CAPTCHA is an automated test used to distinguish interactions that are probably human from particular activities performed by software.

Its name stands for Completely Automated Public Turing test to tell Computers and Humans Apart. It may present a visible challenge or combine signals to estimate automation risk. It does not verify a person’s identity, prove conclusively that they are human or block every bot.

CAPTCHA history

The term CAPTCHA was coined around 2000 by a research team consisting of Luis von Ahn, Manuel Blum, Nicholas Hopper and John Langford. It was associated with the idea of a reverse Turing test because a machine generates and evaluates a test that needs to be solved by whoever is attempting to access a function.

Early systems were mainly based on recognising distorted characters. They sought to use visual tasks that were more difficult for the software available at the time.

Optical recognition, machine learning and solving services reduced the effectiveness of many static challenges. Systems developed to use images, audio, interactions and signal analysis. Their difficulty needs to be reviewed as both automation capabilities and the effects of the test on people change.

reCAPTCHA is a particular service that has used different approaches over time. It is not a synonym for every CAPTCHA, and its versions do not all operate through the same test.

Types of CAPTCHA

Mechanisms may be classified according to the test or signals they use:

  • Distorted text: It asks a person to recognise and enter characters represented in an image. It may make reading difficult for people and software, but can also be solved using optical recognition.
  • Image selection: It asks users to identify objects or features within a set of images. Its outcome depends on the clarity of the instruction, visual quality and automated recognition capabilities.
  • Audio: It plays words, letters or numbers that need to be interpreted. It may provide an alternative to a visual test, although noise, language and hearing difficulties can also prevent completion.
  • Simple questions or tasks: It uses calculations, logical relationships or brief instructions. Simplicity may support human interaction, but many of these tasks are also easy to automate.
  • Checkbox or interaction: It asks for a checkbox or another action and combines that interaction with additional signals. The precise position of a click does not by itself determine whether a bot is present.
  • Risk analysis without a visible challenge: It assesses signals from the request or behaviour and returns a score or classification. For example, reCAPTCHA v3 provides a score that the website can use to decide which response to apply.

One implementation may display a challenge only when previous signals exceed a defined risk level.

CAPTCHA scope

A CAPTCHA is a control against particular forms of automation, not an authentication system. Solving one does not establish a name, account or authorisation to access a resource.

Social login, a code sent by SMS and biometric recognition are used to authenticate or verify an account or factor. They may be combined with a CAPTCHA but are not CAPTCHA types.

Hidden fields or honeypots, rate limits, timing analysis, blocklists and pattern detection are complementary anti-bot controls. Some operate without presenting a test to the person and may also produce false positives.

Protection needs to correspond to the abuse being addressed, such as automated registrations, form submissions, mass account creation or repeated access attempts. The same mechanism does not provide equal effectiveness against every bot or in every context.

CAPTCHA impact

Visual, auditory, linguistic or cognitive challenges may prevent a person from completing a legitimate action. The WCAG accessibility documentation states that a non-text CAPTCHA needs a text alternative identifying its purpose and alternative forms adapted to different modes of sensory perception.

Keyboard operation, compatibility with assistive technologies, available time, error recovery and an alternative route that does not depend on the same ability also need to be considered.

Risk-based systems may process signals related to the request, device or behaviour. Their integration requires assessment of which information is collected, who receives it, how long it is retained and which privacy and consent controls apply.

A CAPTCHA should be considered a defence-in-depth measure. The OWASP authentication guidance notes that it can increase the cost of an attack but should not be treated as absolute prevention.

Evaluation may include blocked attempts, errors, abandonment, completion time, legitimate requests rejected and attackers’ ability to bypass or outsource the challenge. Reducing automation does not compensate for disproportionately preventing legitimate access.