Cloudflare leaves Google reCAPTCHA

Cloudflare announced that it has abandoned Google's reCAPTCHA service and is now using hCaptcha.


Cloudflare as a service, offers many features to those who have a website. One of them, for example, is the captcha which acts as a firewall. Prevents malicious traffic of bots, allows movement only by people as it displays a captcha, if it detects movement that may be malicious or illegal.

Captcha is a fully automated test that aims to determine if the person making an online request is a human or a robot (Captcha = Completely Automated Public Turing Test to Tell Computers and Humans Apart). It is usually presented at the end of a request as a verification step. Ideally, captchas are designed so that people can easily pass them, while bots respectively will fail.

Surely you have been asked by a website to either fill in a word whose letters are in an image, or to suggest by a series of images depicting a bicycle for example etc. These are all different techniques for Captcha.

Cloudflare used the reCAPTCHA service (acquired by Google in 2009). Until now, the use of reCAPTCHA was free for the companies that implemented it. Google, in turn, gained something in return for using the service to train visual recognition systems. The choice was business-wise, as it was free, and it escalated thanks to Google's vast network of servers and was effective (according to Cloudflare, though at times had side effects).

Of course, privacy concerns arose from the earliest days, as Cloudflare customers were concerned as the reCAPTCHA service was managed by Google. In addition, Cloudflare noticed that reCAPTCHA had problems in some areas, such as China, as Google services often (or always) have been excluded there.

On the other hand, Google announced in 2020 that it will start charging for the use of reCaptcha. Cloudflare started looking at other captcha services to find a suitable alternative, as it would be very expensive to continue using Google's solution.

And so Cloudflare chose it hCaptcha after according to her provides several reasons for this:

  1. The company does not sell personal data and collects only minimal.
  2. The performance was "so good, better than expected".
  3. Includes solutions for visually impaired and "other users with accessibility problems".
  4. Supports Privacy Pass.
  5. The solution works in areas where Google has been blocked.
  6. The hCaptcha team is "agile and responsive".

The hCaptcha business model is similar to Google's. The company charges customers who need "image classification data". Both companies agreed on a different business model due to the size of Cloudflare. Cloudflare decided to pay hCaptcha and push most of its technical load into its own platform to make sure the solution would work properly.

It remains to be seen how well this change will go.

