CAPTCHA is Dead: The Ticketing Industry's Bot War

2025-05-25

Ticketing websites face a persistent challenge: bots used by scalpers to snatch tickets. Traditional CAPTCHAs, such as image and audio recognition, have been defeated by advanced machine learning. Behavior-based anti-bot technologies, while effective, compromise user privacy; while proof-of-work methods are too inexpensive for scalpers. The author proposes a "BAP theorem," stating that anti-bot systems can only satisfy two out of three properties: "bot-resistance," "accessibility," and "privacy." Ultimately, websites must choose between high privacy and high security; technical solutions alone are insufficient. Legislation and social approaches might be more effective.