Gesture Dynamics CAPTCHA Emerges as Privacy-Focused Drop-in Alternative to reCAPTCHA
A new open-source project introduces a gesture-dynamics CAPTCHA designed as a drop-in replacement for reCAPTCHA. Instead of forcing users to identify buses or traffic lights, the system asks visitors to draw an arbitrary gesture lasting roughly ten seconds.
The core idea is to classify motor behavior rather than visual content. Eight statistical features, including velocity variance, pause entropy, rhythm irregularity, and correction count, are extracted from the gesture. A local gradient-boosting model handles clear cases in milliseconds, while an LLM is invoked only for uncertain borderline decisions.
The widget is delivered inside an iframe served from the vendor origin. This architecture avoids CORS restrictions and Origin-based bot filters that would arise if the client page called the API directly. Each integration uses a public key bound to an allow-list of domains and a secret key kept on the customer server for token verification.
Privacy protections are explicit: raw coordinates never leave the browser, no image datasets are collected, and no biometric templates are stored. The resulting token carries no user identity and expires after 120 seconds. Because no Google services are involved, sites avoid both data-transfer concerns under GDPR and the need for additional cookie banners.
Integration requires two lines on the client side and a single server-side verification call modeled after reCAPTCHA. On success the loader injects a hidden field named aptogon-response; the backend then posts the token to the verification endpoint using the secret key.
The project acknowledges its limitations. A motivated attacker could eventually imitate human dynamics, and the widget alone does not stop distributed floods through residential proxies. Accessibility accommodations for motor impairments are included, with ongoing collection of feedback to refine the models.
In the Russian market the solution positions itself against Yandex SmartCaptcha, targeting developers who need self-serve privacy controls and cannot rely on reCAPTCHA due to availability or regulatory constraints. Source code, documentation, and live demos are available under the AGPL-3.0 license with a free tier of one thousand verifications per month.
Related articles
CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge
Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.
Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files
Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.
Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks
Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.
New Obfuscation Method Dissolves Personal Data Records in Layer of Plausible Variants
A Russian information security researcher has proposed a data protection technique that renders stolen personal records unusable even after full compromise. The approach mixes real data such as phone numbers, emails, passports, addresses, INN and SNILS with vast numbers of semantically valid alternatives. Attackers receive nearly complete information including a 361-character message containing PIN codes and word order, yet lack the secret vector space and reconstruction algorithm required to identify the correct record. Without these components, brute-force attempts produce millions of plausible results with no architectural method to verify accuracy. The method is presented as an alternative to traditional encryption when data must remain accessible yet protected against extraction. A public sandbox is available for testing the approach.