Google's Webcam reCAPTCHA Bypassed with Stock Photo
Google's experimental hand-scan reCAPTCHA, designed to verify humanity, was swiftly defeated by testers using a simple stock photo and virtual camera.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

Google's latest attempt to combat sophisticated bots, an experimental webcam-based reCAPTCHA requiring a hand scan, has been embarrassingly defeated by testers using just a stock photo and OBS Virtual Camera. This critical flaw, achieved without live video or AI, exposes the vulnerability of the system and intensifies the ongoing "CAPTCHA arms race."
Currently in limited testing as part of Google Cloud Fraud Defense, the controversial system prompts users for camera access to perform a hand gesture, such as waving. Google's machine-learning model extracts 21 hand-knuckle coordinates to verify a real person. Despite Google's assurances that footage is deleted immediately, not linked to identity, and contains no audio, privacy advocates remain deeply concerned about biometric data collection and the necessity of trusting Google with such sensitive information.
The ease of this bypass raises serious questions about the reCAPTCHA's efficacy and the future of online verification. Rather than providing robust security, this gesture reCAPTCHA appears to add friction for legitimate users while offering minimal resistance to determined attackers. Accessibility concerns for users with disabilities or in poor lighting also persist, even with traditional alternatives available. This incident highlights the ongoing challenge for tech giants to innovate bot detection without compromising user privacy or creating easily exploitable vulnerabilities. Secure and respectful "liveness detection" remains a critical, yet elusive, goal.