I'm not sure how things will work out the next time though.
Most captcha solutions are defeated by services like 2captcha.net and generally aren't the most privacy respecting.
Bots are very likely to use VPNs, so captcha services make things a real pain in the ass for anyone connecting from a VPN.
It's the same story with Tor. Coming from a VPN/Tor is a strong signal that you're more likely to be a malicious user.
So when you fail, it's not really saying you're wrong, it's saying you're not like most.
Someday, I'm hoping some sociologists look for evidence of socioeconomic discrimination in captcha implementations.
In my experience, performing the exact same actions with your mouse in Mountain View leads to a completely different outcome than it does in lower income areas (red-voting white, ethnic minorities, etc) surrounding the Bay Area.
While those CAPTCHAs present a surface narrative of you having to get the problem correct, that's not how they really work. After all, it's not like they are creating those problems by hand. They're pushing the images through computers. You don't even know that what the CAPTCHA server considers correct is even close to objectively correct.
Really it's just a hook to engage you to collect a wide variety of streams to try to detect whether or not you are a human, like reaction speeds, how the mouse moves, etc. The correctness of your selection is only one small signal, and not even necessarily a large one.
The answer is, stop overthinking it. Your overthinking it is probably sending a signal that you're not a human because it's got all your timings wrong. Do what most humans do: Halfassedly click at the problem until it seems rightish and then click "Submit". Does the sliver of tire that shows up in the bottom right tile count? The human response to that question is "Who cares you dumb computer let me through to the content already", so, to maximize how human you look to the algorithm, channel your fellow human's feelings. If you feel frustrated at the CAPTCHA problem and wiggle your mouse angrily and maybe overshoot some of the squares you mean to click, so much the better and more human looking.
But, it pisses me off to no end that I can't use my fucking keyboard the way it is supposed to be used (which is a far superior design to the "normal" setup) to view some websites because it doesn't "look" human to the fucking server who expects me not to be a statistical outlier. As someone who has always been an outlier, I kind of hate the algorithmic future we live in and are headed even further toward. This is why we can't have nice things.
The forum folks may be able to provide a solution.
Surely this is just your preference and the setup isn't objectively better. I can see see some people prefer moving a mouse with a keyboard but they likely wouldn't be as quick/precise as people with an actual mouse.
It will work to make ad-blocking difficult enough that most people don't bother anymore.
I don't have any knowledge of what spammers' financials are like, but it's possible that even 0.01c/captcha would still be impactful if the click rate is low enough.
Probably the best way to start tuning the PoW difficulty is just by starting out with what users are willing to tolerate - e.g. 3s solve time on the median mobile device. The gap between mobile and desktop devices has significantly lessened over the past decade, so desktop-grade equipment won't have that much of an advantage - say 1s per captcha, which is a lot for a spammer who would otherwise be able to send out dozens of spam per second.
It's not about making spam impossible, but about making it unprofitable enough that the criminals go elsewhere. Economic warfare.
It might work for spammers who really are just making billion of attempts, but then again if they are making that many attempts then you can block on the IP level.
The basic idea is that they'll happily let you sneak a few spam messages through iMessage if you're willing to spend a few hundred dollars on a burner iPhone. This is one reason why they're so resistant to allowing gateway protocols between iMessage and third party devices or RCS.
Hashcash[1] was invented two and a half decades ago and is still the best solution. It doesn't require manual work or user privacy invasion and deters mass spammers.
The comms is encrypted on the bus using strong cryptography, so you can’t sniff it.
All these software blobs are signed and encrypted, you can’t replace it without the signing key.
Only where the the adverts are embedded with an encrypted single stream.
Hard to do targeted advertising that way though.
It is a lever that you can pull that's better than nothing though.
So long as you can run code on your CDN edge servers - which Youtube undoubtedly can - there's no technical reason this couldn't be done.
Hopefully HDMI/HDCP splitters will add an adblock feature as well.
Even for level3, i can only inagine that the amount of obfuscation must be pretty intense.