We are adding another CAPTCHA vendor and helping our customers migrate from Google's reCAPTCHA to hCaptcha.
We continuously evaluate our security measures to ensure they align with the evolving landscape of threats.
After carefully evaluating several different CAPTCHA providers, including rigorous testing by our threat research team, hCaptcha surfaced as a leading solution that we would like to use.
Our decision to switch to hCaptcha is driven by several factors.
First, we wanted to ensure we use the most updated CAPTCHA service.
We use reCAPTCHA Version 2, but because reCAPTCHA Version 3 isn't GDPR compliant, we cannot use it.
As a cybersecurity company, we prioritize compliance with global regulations to ensure the utmost security for our users.
hCaptcha doesn't rely on personal user data or historical interactions for its functionality, which aligns with our commitment to respecting user privacy.
This transition to hCaptcha addresses the market's concerns about reCAPTCHA allowing two domains to access the same cookie data set to enable ad targeting.
hCaptcha is also globally available, including in China, a region not supported by Google.
By moving to hCaptcha, we aim to streamline our processes and provide more efficient service to our users.
Some use cases of these automated attacks include Distributed Denial of Service, brute force login attacks, web scraping, and more.
CAPTCHAs are a type of challenge that does require some human intervention.
While we strive to only present a CAPTCHA as a last measure in a varied set of transparent challenges, we provide our customers with complete control over how they would like to manage their security measures.
This means customers can still choose to issue a CAPTCHA challenge as a security rule.
As automated traffic becomes increasingly sophisticated, Imperva Advanced Bot Protection adds even more transparent challenges as part of its multi-layered detection approach.
These significantly reduce the need to serve a CAPTCHA. In fact, on average, with Advanced Bot Protection, legitimate users will not be served a CAPTCHA on 99.999% of requests, ensuring a frictionless online experience without compromising security.
While CAPTCHAs still play a vital role in cybersecurity, we recognize they aren't perfect.
We are committed to minimizing and, hopefully, eliminating the number of CAPTCHAs we issue altogether.
Our transition to hCaptcha is a significant step in this direction.
This Cyber News was published on www.imperva.com. Publication date: Thu, 21 Dec 2023 17:43:04 +0000