INSIGHTS 

How to stop bots getting past reCAPTCHA using v3. 

Cybersecurity is the number one threat to companies in 2024 with their websites facing a constant barrage of automated attacks from millions of malicious bots. These bots are designed to wreak havoc; from stealing user data and spamming contact forms to scraping valuable content and disrupting essential services.

With the sheer number of bots out there you may be thinking what can I do to combat this threat? The good news is that website owners have a roster of tools at their disposal to help, most rely on CAPTCHAs (Completely Automated Public Turing test to tell Computers and Humans Apart).

What is a reCAPTCHA?

reCAPTCHA is a free service by Google that helps distinguish between humans and those pesky internet robots. I’m sure you have all experienced this when a website presents a challenge that may seem blatantly obvious and easy for humans to solve but difficult for bots, helping to ensure that only real people interact with your website.

When most companies think of this security option they traditionally use reCAPTCHA v2 as it was the go-to option. It presented users with a checkbox “I'm not a robot" and sometimes an image recognition challenge, requiring users to identify objects like traffic lights or bicycles. I’m sure we have all experienced the dread of overthinking if an object has leaked into another square and we will be penalised for this pathetic attempt.

The evolution of bot detection from v2 to v3. 

Whilst mostly effective, v2 has had its drawbacks, one being user experience, where clicking checkboxes and solving image puzzles can disrupt the UX on your website and frustrate legitimate visitors. This could potentially cause them to click off your site or affect their perception of your brand. It could also cause issues to arise over privacy concerns as v2 relied heavily on cookies, and as we all know over the past 10 years there has been a rise in concerns around the collection of user’s data, which has resulted in stricter data privacy regulations such as GDPR.

Introducing reCAPTCHA v3 - the next level in bot combat.

Recognising these limitations, Google introduced reCAPTCHA v3. Building on the system they introduced some snazzy new features. Invisible protection means that v3 operates silently in the background of your website, analysing user behaviour and assigning a score based on the likelihood of that user being human or not. This has eliminated the need for monotonous checkbox clicks or image challenges, providing a seamless and undisturbed UX.

Advanced threat detection analyses a wider range of user interactions than v2, making it more adept at catching more sophisticated bots that have been programmed to mimic human behaviour. Finally, customisable security provides a risk score, allowing you, the owner, to set a threshold for blocking suspicious activity. This level of control allows you to tailor security measures to your brand's website-specific needs.

The rise of AI and the need for multi-layered defence. 

Whilst v3 is a significant improvement to the outdated v2 system, advancements in AI mean some bots can even bypass the more difficult v3 challenges. This underlines the fact that reCAPTCHA alone is not the answer and that you should consider a layered security approach. One of the layers that you could consider as an additional security measure is a Honeypot. Honeypot consists of form fields that are invisible to likes of you and me but not to a bot and they may fill them out, whereas a human wouldn’t. 

Introducing our Prestashop 1.7+ module 

Our Teapot Devs have developed a Prestashop module (1.7+ module) which seamlessly integrates reCAPTCHA v3 with your contact and registration forms, providing robust protection against bots. Here are some of the key features of the module:
  • Easy integration

          The module is straightforward to install and configure, requiring minimal technical expertise.

  • Customisable security

          Set the reCAPTCHA v3 score threshold to match your desired level of security.

  • Honeypot protection
          The module includes a built-in honeypot to further deter bots.
  • Flexible implementation
          Choose to activate reCAPTCHA v3 on either the contact form, registration form or both.

Other forms of security beyond utilising reCAPTCHA 

While reCAPTCHA v3 offers a powerful solution, no security measure is foolproof from online threats. It's crucial to stay informed about evolving bot threats and adapt your security strategy accordingly. Consider combining reCAPTCHA with other security measures like IP address blocking and regular website monitoring.

By implementing a combination of reCAPTCHA v3, honeypots and other security practices, you can create a formidable defence against bots, protecting your website and safeguarding your valuable data.

If you have any questions or require assistance implementing our Prestashop module, feel free to Contact us today.

Back to Insights

Mailchimp stuff.

Registered in England & Wales. Company No. 7945108. VAT Registration No. 102 579 529.