SuckButtBecause some things just suck

The Internet Sucks

Select every square containing a traffic light, including the pole

The puzzle is not testing whether you are human. It is a risk score, and the pictures appear when the score is ambiguous.

Businesswoman working on laptop with Android 6.0 Marshmallow webpage open.
Photograph by Christina Morillo via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

This is written to be used rather than admired. Each section below is a decision about captcha challenges, and each one has a default.

Before you start

  • Modern systems score behaviour first and show a challenge only when uncertain.
  • Privacy tooling and unusual networks raise the score and trigger more puzzles.
  • Image challenges are a known accessibility barrier with imperfect alternatives.

The puzzle is the fallback, not the test

Contemporary bot detection scores a visitor using network reputation, browser characteristics, cursor movement and prior behaviour before showing anything. A confident score lets the visitor through invisibly, which is why most people encounter these systems without ever seeing a puzzle.

The image grid appears when the score sits in an uncertain band, so being asked repeatedly is a statement about your setup rather than about you. That is why the same person sails through on a home connection and is interrogated on a public network or through a privacy service. Understanding this reframes the whole experience, because the puzzle is a symptom of a judgement that was already made.

What raises your suspicion score

Shared exit addresses, whether from a corporate network, a mobile carrier or a privacy service, pool many users behind one reputation. Blocking scripts, spoofing browser characteristics or disabling cookies removes signals the system uses to build confidence, which increases uncertainty.

Unusual browsers, older versions and heavily customised configurations look statistically like automation because automation is also unusual. Rapid, precise interaction patterns read as scripted, which is an ordinary problem for fast keyboard users and for anyone using accessibility tools. The uncomfortable summary is that privacy-protective and accessible configurations are systematically penalised by design rather than by accident.

The labelling side of it

Early text challenges were used to digitise printed books, with the recognised word verifying the user and the unrecognised one contributing a transcription. Image challenges have been used similarly for training data, which is why the categories tend to match whatever machine vision problem is current.

Traffic lights, crossings, buses and vehicles are the recurring categories, and their relevance to road scene understanding is not a coincidence. This is a legitimate arrangement in the sense that it is well documented, and it does mean the work is unpaid and unavoidable. It also means the puzzles get harder as the models improve, since only the cases the model finds difficult are worth asking about.

Accessibility is the genuine failure

Image grids exclude blind and low-vision users entirely, and audio alternatives are frequently distorted to resist automated transcription. Distorting audio enough to defeat speech recognition also defeats a great many humans, which is an unavoidable consequence of the approach. Motor impairments make timed drag-and-slide challenges difficult, and cognitive differences make ambiguous category judgements genuinely unfair.

Accessibility guidance requires an alternative, and the alternatives provided are often measurably worse than the primary route.

This is one area where the criticism is not really about annoyance, since the exclusion is documented and the remedies are weak.

The alternatives that are arriving

Cryptographic attestation approaches let a device prove it is a genuine device without solving anything, which removes the puzzle entirely. The trade is that attestation ties access to hardware and platform vendors, which concentrates gatekeeping in a small number of companies.

The bit they bury in the confirmation email: proof-of-work challenges make automation expensive rather than impossible, and they cost battery on the visitor's device instead of time. Rate limiting, account age and payment history are quietly effective and are unavailable for anonymous first-time visitors. Every approach trades away either privacy, accessibility or effectiveness, and no current option avoids all three.

Seeing fewer of them

Staying signed in to a browser account and keeping cookies for sites you use regularly builds the reputation that avoids challenges. Using a mainstream browser at a current version reduces the fingerprint oddity that pushes a score toward the uncertain band. If you use a privacy service, some offer a signed access token that skips challenges without revealing identity, which is worth enabling.

On a corporate network the score is shared with everyone else on it, so there is genuinely nothing you can do individually. And when the grid appears, the answer usually includes the pole, which is the only piece of practical advice this article can honestly offer.

The takeaway

The grid is a symptom of your score, not a test of your species.

None of this is an accident. Somebody drew this flow and somebody approved it.

Questions readers ask

Why do I get so many more puzzles than other people?

Your risk score sits in the uncertain band. Shared network addresses, privacy tooling and unusual browser configurations are the common causes.

Does the puzzle train an AI?

Image challenges have been used to generate labelled training data, which is documented. It is also why the categories track current machine vision problems.

The Internet Suckscaptchasecuritybotsaccessibility
More in The Internet Sucks
Jhilik Mahapatra
Contributing writer, SuckButt

Jhilik writes about everyday irritations and believes packaging is a conspiracy.

Also by Jhilik Mahapatra