{"id":997101,"date":"2020-04-23T15:02:00","date_gmt":"2020-04-23T07:02:00","guid":{"rendered":"https:\/\/geetests.com\/article\/why-captcha"},"modified":"2025-09-15T14:36:16","modified_gmt":"2025-09-15T06:36:16","slug":"why-captcha","status":"publish","type":"post","link":"\/en\/article\/why-captcha","title":{"rendered":"Why CAPTCHA is a Necessity for Cybersecurity in 2021"},"content":{"rendered":"<div class=\"vgblk-rw-wrapper limit-wrapper\">\n<p class=\"ql-align-justify\">Bots are a two-decade-old problem, and today, over 50% of the internet is estimated to be bot traffic, but why should you care? If you are not prepared, bad bots can be extremely damaging to your online business operations as well as your reputation.<\/p>\n<p class=\"ql-align-justify\">In 2018, HSBC Bank, one of the largest financial services organizations in the world, has been the victim of a bot attack,\u00a0<a href=\"https:\/\/www.americanbanker.com\/news\/hsbc-suffers-data-breach-on-small-number-of-online-accounts\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>confirming the data breach<\/strong><\/a> affecting its U.S. customers<span class=\"ql-size-16px\">&#8216;<\/span> private information. Cybercriminals used a credential stuffing attack to gain unauthorized access to thousands of user accounts through large-scale automated login requests. In the aftermath of the attack, HSBC enhanced its authentication for online banking by deploying a captcha on its login page, limiting access to genuine humans only.<\/p>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">Account takeover attacks, endless spam comments and emails, ticket scalping, abusive website traffic, scraping of your valuable website data and content are just some of the damages bots can cause. For underprepared online businesses, it can take months before a breach is identified, causing<strong>\u00a0<\/strong><a href=\"https:\/\/www.ibm.com\/security\/data-breach  \" target=\"_blank\" rel=\"noopener noreferrer\"><strong>$3.9 million losses per breach on average<\/strong>.<\/a>\u00a0Would you know if sophisticated bots were already abusing your online business?<\/p>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">\n<h2 class=\"ql-align-justify\"><strong>How CAPTCHA Prevents Bot Attacks?<\/strong><\/h2>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\"><a href=\"https:\/\/blog.geetest.com\/en\/article\/What-is-captcha\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>CAPTCHA<\/strong><\/a>,\u00a0also referred as a reverse Turing test, is originally developed as an automated test to distinguish whether an online visitor behind a request is a genuine human or an automated computer program a.k.a., a bot. Deployed at operational gateways such as login, sign up or form submission processes, captchas stop automated programs from accessing and abusing your website. However, not all captchas are equal, as the bot threats became more sophisticated,\u00a0<a href=\"https:\/\/blog.geetest.com\/en\/article\/captcha-evolution\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>captchas have evolved<\/strong><\/a>\u00a0as well.<\/p>\n<p class=\"ql-align-center\"><img decoding=\"async\" src=\"https:\/\/geetests.com\/wp-content\/uploads\/2025\/09\/prevent-bot-fraud.gif\" alt=\"\"><\/p>\n<p class=\"ql-align-center\">\n<h2 class=\"ql-align-justify\"><strong>AI Makes the CAPTCHA You Know Obsolete<\/strong><\/h2>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">In order to bypass captcha, a computer program has to do what a human can do; therefore, as AI technology improves, captcha challenges as we know become ineffective.<\/p>\n<p class=\"ql-align-justify\">The idea behind the traditional captchas was that the machines were simply incapable of recognizing distorted texts. As the OCR (Optical Character Recognition) technology improved over the years, <a href=\"https:\/\/www.zdnet.com\/article\/google-algorithm-busts-captcha-with-99-8-percent-accuracy\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>machine programs became better<\/strong><\/a><span style=\"color: #ff0000;\">\u00a0<\/span>at recognizing distorted texts than humans, and <a href=\"https:\/\/blog.geetest.com\/en\/article\/why-text-based-captcha-cannot-satisfy-the-needs-of-enterprises\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>text-based captcha became obsolete<\/strong><\/a>. Even though more innovative captcha challenges that are based on recognizing images, numbers, or various objects became more popular in recent years, these methods still rely on a one-dimensional logic and are static in nature.<\/p>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">At present, using machine learning technology, creating a computer program that can bypass these challenges is rather easy, which makes the captchas you know obsolete at preventing modern bot threats.<\/p>\n<p class=\"ql-align-center\"><img decoding=\"async\" src=\"https:\/\/geetests.com\/wp-content\/uploads\/2025\/09\/how-to-stop-bad-bots.jpg\" alt=\"\"><\/p>\n<p class=\"ql-align-justify\">\n<h2 class=\"ql-align-justify\"><strong>Sophisticated CAPTCHAs for Sophisticated Bad Bots<\/strong><\/h2>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">The third generation captchas, also known as\u00a0<a href=\"https:\/\/blog.geetest.com\/en\/article\/advanced-captcha\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>no-knowledge or advanced captchas<\/strong><\/a> distinguish themselves from the rest by introducing advanced risk analysis into the equation. By analyzing the behavioral characteristics and the environmental information of a visitor, advanced captchas are able to\u00a0<a href=\"https:\/\/blog.geetest.com\/en\/article\/captcha-future\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>distinguish genuine human behavior from computer-generated human behavior.<\/strong><\/a>\u00a0When the comprehensive decision-making system detects a risk, a challenge-response is presented to collect further data about the visitors&#8217; operation and make a final judgment. This approach has two significant benefits.<\/p>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\"><strong style=\"color: #0e101a;\">Security<\/strong><span style=\"color: #0e101a;\">: The integrity of the system relies on the sophistication of its back-end operations where the risk analysis engine runs. Merely answering the challenge will not grant access to a bot, it has to perfectly mimic the human behavior and deceive the risk analysis engine which can be observed over a hundred different parameters. This is not a possible task for modern computer programs to run at scales that would be required for a successful bot attack.<\/span><\/p>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\"><strong style=\"color: #0e101a;\">User Experience:\u00a0<\/strong><span style=\"color: #0e101a;\">For an Advanced CAPTCHA, it is\u00a0<\/span><strong style=\"color: #0e101a;\">not<\/strong><span style=\"color: #0e101a;\">\u00a0<\/span><strong style=\"color: #0e101a;\">about<\/strong><span style=\"color: #0e101a;\"> completing the challenge correctly; it<span class=\"ql-size-16px\">&#8216;<\/span>s\u00a0<\/span><strong style=\"color: #0e101a;\">all about<\/strong><span style=\"color: #0e101a;\">\u00a0the process of completing a challenge. Therefore the challenge-response only presents an opportunity to collect further data about the visitor behavior, which allows the challenge to be more straightforward and user-friendly. Of course, there are<\/span><strong style=\"color: #0e101a;\">\u00a0<\/strong><a style=\"color: #0e101a;\" href=\"https:\/\/www.geetest.com\/en\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>significant differences<\/strong><\/a> <span style=\"color: #0e101a;\">in user experience between different advanced captcha solutions. For example, it can take more than 10 seconds to pass a ReCaptcha challenge while GeeTest captcha takes 1.6 seconds on average.<\/span><\/p>\n<p class=\"ql-align-center\">\n<p class=\"ql-align-center\"><img decoding=\"async\" src=\"https:\/\/geetests.com\/wp-content\/uploads\/2025\/09\/security-vs-user-experience.jpg\" alt=\"\"><\/p>\n<p class=\"ql-align-justify\">\n<h2 class=\"ql-align-justify\"><strong>Why All Detection-Based Bot Mitigation Systems Integrate a CAPTCHA?<\/strong><\/h2>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">When it comes to fighting modern bot threats, the goal for all advanced solutions is the same; to distinguish genuine human behavior from automated human behavior. While CAPTCHA achieves this goal through interaction on operational gateways, some systems detect bots by analyzing the entire website traffic.<\/p>\n<p class=\"ql-align-justify\">Even though these expensive bot detection systems are deployed network-wide and provide security for the whole website -instead of just essential operational gateways- they still encounter large numbers of suspicious traffic.<\/p>\n<h3 class=\"ql-align-justify\"><\/h3>\n<h3 class=\"ql-align-justify\"><strong>How do detection-based systems deal with suspicious traffic?\u00a0<\/strong><\/h3>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">Directly blocking them runs the risk of a high rate of false positives and reduced conversion rates for the website while allowing the suspicious traffic makes the system vulnerable to bot attacks. This is where advanced captcha solutions come into play, making the final judgment on the suspicious traffic and reducing the rate of false positives to the minimum. The Defence-in-depth approach is crucial for maximizing security, and advanced captcha is the first line of defense against automated attacks.<\/p>\n<p class=\"ql-align-justify\">\n<h2 class=\"ql-align-justify\"><strong>Conclusion<\/strong><\/h2>\n<p class=\"ql-align-justify\">\n<p class=\"ql-align-justify\">As online business operations remain to be valuable, the potential financial gains will continue to attract criminals. Empowered by the advancing AI and machine learning technology, cyber-criminals are utilizing increasingly sophisticated bots more and more.<\/p>\n<p class=\"ql-align-justify\">Advanced captchas are vital against the increasing number of sophisticated bot attacks and a necessity to keep the internet ecosystem as we know today safe and trusted.<\/p>\n<p class=\"ql-align-justify\">Towards the mission to keep the internet genuine-human only, user friction is an often overlooked part of the equation. At GeeTest, we\u00a0believe a great security solution should be excellent in not only security but user experience as well.<\/p>\n<p class=\"ql-align-justify\">Learn how the <a href=\"https:\/\/www.geetest.com\/en\/Solution\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>world<span class=\"ql-size-16px\">&#8216;<\/span>s leading enterprise-grade captcha solution<\/strong><\/a>, GeeTest, ensures excellent security and utmost usability.<\/p>\n<\/div>\n<p><!-- .vgblk-rw-wrapper --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious bots take up approximately a quarter of the global web traffic, and CAPTCHA is the first line of defense against these increasingly sophisticated bot threats.<\/p>\n","protected":false},"author":7,"featured_media":996256,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[89],"tags":[],"class_list":["post-997101","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fraud-prevention"],"_links":{"self":[{"href":"\/en\/wp-json\/wp\/v2\/posts\/997101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"\/en\/wp-json\/wp\/v2\/comments?post=997101"}],"version-history":[{"count":2,"href":"\/en\/wp-json\/wp\/v2\/posts\/997101\/revisions"}],"predecessor-version":[{"id":997675,"href":"\/en\/wp-json\/wp\/v2\/posts\/997101\/revisions\/997675"}],"wp:featuredmedia":[{"embeddable":true,"href":"\/en\/wp-json\/wp\/v2\/media\/996256"}],"wp:attachment":[{"href":"\/en\/wp-json\/wp\/v2\/media?parent=997101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"\/en\/wp-json\/wp\/v2\/categories?post=997101"},{"taxonomy":"post_tag","embeddable":true,"href":"\/en\/wp-json\/wp\/v2\/tags?post=997101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}