I have noticed that some CAPTCHA pages, like Cloudflare’s, simply ask you to check a box to proceed. There is no clicking on traffic lights or entering characters. How does clicking on a check box tell them I am not a robot?
I have noticed that some CAPTCHA pages, like Cloudflare’s, simply ask you to check a box to proceed. There is no clicking on traffic lights or entering characters. How does clicking on a check box tell them I am not a robot?
https://developers.cloudflare.com/turnstile/
TL;DR A bunch of heuristics that it’s hard to spoof all of. Fun side effect of this method is that if you spoof your user agent, you’ll often end up locked out in a loop. Lack of a captcha fallback is obnoxious.
Incognito / ublock and vpn will often trigger a loop of captcha
I have been stuck in one its hell you will be hoping this will be the last.
I got stuck in one and couldn’t even search for help because each result where people were complaining about it had a captcha preventing me from entering.
also the subtle but not so subtle ‘we will fingerprint errrrbody’
so what do they do with that data?
Sell it to all the bidders.
in my experience, you can sometimes get away messing a token or two in the user string as long as it is one of the common ones out there. start injecting BeOS and other arcane values in and things get less reliable.