Prove you're human with a wave , not another CAPTCHA.
A gesture-based way to prove a real person is there , swapping the CAPTCHA-and-2FA gauntlet for one quick hand sign, read by a computer-vision model in the browser. The camera feed never leaves your device.
You just want to prove you're human.
It should take a second. Here is what today's login actually asks of you before it lets you in.
Enter your password
The one you reused, then reset, then forgot again.
Wait for a text code
A six-digit number, valid for exactly as long as it takes to arrive.
The phone is in the other room
So is the charger. So is your patience.
Still locked out
Now weighing whether the bank balance was even worth it.
Now solve a CAPTCHA
Squint. Click every square with a traffic light. Fail. Retry.
The code expired
The 30 seconds ended while you were in the other room. Start over.
We prove we're human dozens of times a day. It's exhausting.
Work accounts. University portals. Recipe sites. Every login throws up the same gates: passwords, codes, CAPTCHAs. Each one is a small tax on your attention. Stack them across a day and security stops feeling like safety , it starts feeling like a chore.
Every check is built to stop bots , not to work for people.
Each fix defends against the machine by handing more work to the human:
I dug into why these checks fail , especially the CAPTCHA.
I didn't start with gestures. I started by mapping the CAPTCHA problem space and listening to people describe logging in , in interviews, in observation during real logins, and across Reddit threads where the frustration is raw.
- Blurry, low-quality images caused hesitation and second-guessing.
- Every failed attempt re-triggered the CAPTCHA , repeats drove the frustration, not the first try.
- Tiny targets were painful on phones; people pinch-zoomed just to read them.
- When a check felt unnecessary or invasive, people distrusted , or abandoned , the site.
Everything clustered into five themes.
People want strong protection. They just hate friction that feels pointless.
Under every theme sat the same conflict , and it's the conflict behind every auth product:
Nobody should have to pick.
I explored three ways to prove a human is there.
I sketched three ways to prove a human is present, then weighed each against friction, privacy, and how convincingly it separates a person from a bot.
GestureCAPTCHA: wave to prove you're human.
Instead of squinting at a distorted grid, you make one quick hand gesture , a peace sign, a thumbs up , in front of your camera. The model checks it's a real, live hand and waves you through.
It replaces the CAPTCHA, and can stand in as a friendlier second factor. The camera feed is processed on-device and never saved.
Each design choice came from a user mental model.
I mapped the assumptions people bring to a camera-based check, then designed against each one.
I put the gesture check in front of real people.
The mental models above didn't come from a whiteboard , they came from watching people meet a camera-based check for the first time.
It's a working concept , here's what's real, and the bar it's aiming at.
The bar to beat (today's CAPTCHA, for context):
What this does , and pointedly doesn't , solve.
Trust isn't a feature you add at the end.
Training the model to recognize a hand was the easy half. The real work was getting someone to feel safe letting a camera watch them for a second , and making sure the people a CAPTCHA already fails aren't failed again. That flipped how I design: the feeling comes first, the feature serves it.
It might just feel like waving hello.