Google’s latest attempt to outsmart bots with a webcam-based hand gesture CAPTCHA has already been defeated—using a simple stock photo. The test ignites fresh privacy debates and exposes the escalating arms race against automated systems.
The new system, dubbed "hand gesture verification" (HGV), asks users to grant webcam access. It then records a quick video of a user performing a gesture, like a wave, to prove they are human. Security researchers, however, demonstrated its vulnerability almost immediately.
Using a virtual camera through software like OBS Studio and a stock image of a hand, testers easily fooled the verification system without a physical webcam or a real hand. This simple bypass can be automated, rendering the new CAPTCHA effectively useless against automated attacks.
Flawed Security and Privacy Risks
The swift failure of the hand-gesture CAPTCHA is a textbook example of a persistent problem: advanced automation and machine learning can now defeat most conventional identity verification systems.
The fact that a stock photo bypasses a biometric check suggests this new approach is no more effective than older methods that AI can now solve with ease.
Google insists the recorded videos are only processed for gesture detection, "never" linked to a user's identity, and deleted shortly after verification. The company also claims it does not record audio.