reCAPTCHA v3 checks for humanity in the background

Have you ever had to click on a grid full of images, or transcribe barely readable words to prove to a site that you are human? You may not have to do this anymore; Google has introduced major changes to its reCAPTCHA tests.

Google had a high goal for the 3rd version, which it acquired from Carnegie Mellon almost ten years ago. The company wanted to make the reCAPTCHA process “hassle-free.” No images to click on. No text entry.

The new reCAPTCHA is already working, and Google has completed its task. The test is completely invisible to users.

When you visit a site that uses reCAPTCHA v3, you won’t even know that your humanity is being tested. Everything happens in the background. Only the site you visit and the Google reCAPTCHA servers know that something is happening.

How can Google determine that you are a person, not a bot, without forcing you to do anything?

Because you have already done a lot in your browser. All Google has to do is analyze what you have already done.

Instead of embedding the Google reCAPTCHA code on one page, webmasters are encouraged to add it on multiple pages. This allows Google to more accurately track the behavior of the visitor and, ultimately, to conclude - this is an ordinary user or an attacker trying to compromise the site.

Google calls this background testing “adaptive risk analysis”. Each visitor to the site receives a test score, and he must decide what happens after that. Low ratings (suspicious users) may be forced to take additional tests. It can be calls to reCAPTCHA of the old version or enter a confirmation code sent using a text message.

Users who receive higher ratings are considered legitimate and can go about their business without interruption.

As the ThreatPost blog points out, for reCAPTCHA v3, it will be much harder for scripts and bots to cheat and abuse websites. One test on one page can be quite easy to defeat, but defeating several tests on a site will be much more difficult.

reCAPTCHA v3 can lead to a significant reduction in the number of spam comments, and this is good news for all of us.

In any case, all of us who do not conduct disinformation campaigns.

