Methodology & Stance
How we evaluate verification infrastructure.
This Is A Human operates on a single, uncompromising thesis: The era of inferring humanity through behavioural heuristics or visual puzzles is over. We require cryptographic, device-bound attestation.
Our analysis, tools, and guides are structured around this reality.
Research Methodology
Our data is derived from primary analysis of the automated threat landscape in 2024. We do not rely on vendor marketing claims. We analyze the economics of the attackers.
- Marketplace Analysis: We track the pricing and success rates of CAPTCHA-solving APIs (both human-farm and LLM-based) on dark web and clear web marketplaces. This data informs our CAPTCHA Obsolescence Calculator.
- Framework Decompilation: We actively review the source code of popular open-source anti-detect frameworks (like Puppeteer Stealth) to understand exactly how browser fingerprinting is bypassed.
- Protocol Auditing: We evaluate standardized protocols like WebAuthn not just on cryptographic soundness, but on the friction of implementation for relying parties.
The Editorial Stance
We reject the industry standard of "acceptable bot traffic." If a system can be bypassed trivially via API, the system is fundamentally broken, regardless of its historical success.
We evaluate mitigation strategies across three axes:
- Attacker Cost (Friction): Does this mitigation strategy force the attacker to spend more money (compute, proxy bandwidth, hardware) than the value they extract?
- User Accessibility (Tax): Does this mitigation strategy punish legitimate users? Visual CAPTCHAs are an unacceptable accessibility tax.
- Cryptographic Certainty: Does this mitigation rely on guessing (heuristics), or does it rely on mathematics (public key cryptography)?
Contact
For corrections, data updates, or to submit a new protocol for review, please review our standard Guides repository.