ACSC

ARE YOU HUMAN? PROVE IT.

By The Most Secure Man Alive | WISECLICK Ambassador

There's a kind of criminal who never studies computers. He studies habits.

He knows you stopped reading the "verify you are human" box years ago. Everyone did. And this May, on the websites of real Australian businesses, he cashed that in.

I'll show you his trick. But it only makes sense once you know what that little box actually is — and fair warning: you'll never click one the same way again.

The box was built around 2000 to keep spam robots out of free email. Squiggly letters, type what you see. A test only a human could pass, administered — here's the joke folded into its name — by a machine that could never pass it itself.

Then in 2007, the box quietly became a job.

It started showing two words. The first was the test; the machine knew the answer. The second was a photograph of a word from an old book that computers couldn't read.

Your first answer proved you were human. Your second answer was unpaid work.

You, personally, helped digitise The New York Times and millions of old books, ten seconds at a time, between invoices. Half a million hours of it a day, across all of us. Nobody ever mentioned it. The traffic lights and crosswalks that came later? You were teaching cars to see.

And then the students out-graded the teachers. The machines we trained now beat us at the are-you-a-robot test. Solving it too perfectly is itself a robot signal — that hesitation over the last sliver of traffic-light pole is the most human thing you do all day.

So the industry quietly gave up. The plain checkbox that now waves you through on one click isn't testing you at all. It inspects your browser before your finger moves.

The click is ceremony. The examiner stopped marking the exam years ago — he kept the hall open because we kept turning up.


Our criminal read all of this the way a pickpocket reads a train timetable.

If the test is ceremony, the ceremony can be staged. So he breaks into a real Australian business website — picture the florist's, the accountant's, the tradie's booking page; the ASD doesn't name names — through one plugin nobody updated, and hangs a pixel-perfect copy of the box on it. You arrive trusting the page, because you should. It's real. Verify you are human. You click, same as the last thousand times.

The page slips a command into your clipboard. Pages are allowed to do that; it's the "copy discount code" feature.

Then his box does the one thing no real check has done in twenty-five years. It gives you instructions. Windows and R. Ctrl and V. Enter.

Three keystrokes — your hands — and a command you never read is gathering saved passwords, cards, and the logins that keep you signed in to everything, while the screen looks perfectly normal. The Australian Signals Directorate published the alert in May.

So keep this line. It beats every version of this trick:

A real check never leaves the browser.

Anything that asks you to open a window, press keys, paste, run — that isn't a test anymore. Those are orders. Close the tab.


Now open the other email. The one from your antivirus, due again, filed under "later".

You've renewed it since dial-up and nothing bad has ever happened, so you've fairly concluded it works. You're right — and it has likely earned those renewals. For most of its life, an attack was a file: something dodgy arrived, got checked against the known troublemakers, and got turned away at the door.

But look again at the florist's website. This attack doesn't start with something arriving. It starts with you — the owner, typing the command yourself, with your own permissions. The box even asks you to run it as administrator, politely. The ASD's alert says the quiet part in plain type: attacks you execute yourself can slip past some of the protections standing guard.

Now, some antivirus products have grown new senses for exactly this — they watch how things behave, not just what arrives. Some haven't. Many sit somewhere in between. And here is the uncomfortable truth about that renewal email: almost no owner knows which kind they're paying for. The renewal buys the ritual. Nobody reads the exam paper.

The criminals aren't betting your antivirus is old. They're betting you've never asked.

Here's my industry's confession, and I'd rather make it than dodge it. In 1999 we told you antivirus made you safe, and we never rang back when the world changed. Consider this the call.

I'm not telling you to cancel anything — fear is a poor adviser, and warnings don't change behaviour anyway. Questions do. So when that renewal surfaces, ask it one thing before you pay:

"If I'm tricked into running the command myself — what do you do?"

Sit with whatever comes back. Protection built for this decade watches how things behave once they're running — whoever started them, at 2pm or at 9pm on a BAS night. That's the standard our memberships sit on, and even then we layer it with backups nothing can rewrite, because no single guard has ever deserved blind faith. But the question is yours now, and it works on any product. Including ours.

And if you own a website yourself — WordPress, like four in ten on earth — those borrowed shopfronts belonged to people exactly like you, and the fix takes fifteen minutes. We've put the routine on its own page, free, no email address, no catch: The 15-Minute Shopfront Check.

Want to know where you actually stand?

No scare tactics, no technical lecture — a plain-English walk-through of what's open, what's already shut, and what to see to first. Including the honest answer to the renewal question.

30 minutes. No tech knowledge needed. $149.

Take the Ransomware Readiness Check →

The pause is free. Knowing where you stand is $149.

Understand your exposure. Know what matters most.

Twenty-five years ago we built a test to keep the machines out. The machines learned to pass it. The criminals learned to perform it. Which leaves the two things nobody can fake or automate: the pause before you click, and the question before you pay.

I've used both for twenty-five years. Neither has ever once been wrong.

Stay protected, my friends.
— The Most Secure Man Alive


Frequently Asked Questions

1. What is a fake CAPTCHA attack?

Criminals inject a counterfeit "verify you are human" box into a legitimate website they've compromised. Clicking it loads a command into your clipboard; the box then instructs you to paste and run it, installing malware that steals passwords and logins. Researchers call it ClickFix; the ASD published an alert about it hitting Australian websites in May.

2. Will my antivirus stop a fake CAPTCHA attack?

It depends on the product, and that's the honest answer. The ASD notes that attacks a user executes themselves can bypass some preventative controls. Antivirus that only inspects arriving files struggles here, because the command runs with your own permissions; products with behavioural monitoring stand a better chance. The one question worth asking your provider: "if I'm tricked into running the command myself, what do you do?"

3. I followed the steps on one of these boxes. What should I do?

From a different, clean device, change your important passwords — email and banking first — and turn on two-step login as you go. Run a reputable scan on the affected machine, but treat it as a starting point rather than an all-clear. Then report it through ReportCyber at cyber.gov.au.

4. Can just seeing the fake box infect me?

No. Looking at the page does nothing on its own, even if it loaded your clipboard. The attack only works if you run the command. Clear the clipboard, close the tab, carry on.

5. I have a real CAPTCHA on my website. Does that protect my visitors?

No — the fake boxes are injected after a site is broken into, regardless of what's already on the page. What protects your visitors is your site staying patched: updates on, plugins current, unused ones removed. The 15-Minute Shopfront Check walks through it.

6. What does CAPTCHA stand for?

Completely Automated Public Turing test to tell Computers and Humans Apart — a test administered by a machine that could never pass it itself. It was invented around 2000 at Carnegie Mellon University to stop spam robots mass-registering free email accounts.

7. Why did CAPTCHAs ask about traffic lights and crosswalks?

Your answers labelled photographs for machine-vision training — the things a self-driving car needs to recognise. Earlier, the squiggly two-word tests digitised old books and The New York Times archive. Every answer was ten seconds of unpaid work.

8. Why do so many websites now use the one-click "verify you are human" checkbox?

Because the puzzle era ended — software now solves those faster than people do. The modern checkbox quietly examines your browser before you click; the click itself is largely ceremony. Its recent spread is mostly websites defending themselves against a boom in automated scraping.


Get the next Dispatch delivered to your inbox

Reading next

Leave a comment

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.