Prove you are human on searching


Description of the issue: “Prove you are human” when using google search
How can this issue be reproduced?

use brave browser, go to google and make 2 searches.
the ‘prove you are human’ from brave pops up.

this is SO ANNOYING. I’m about to turn brave off and go back to another browser.
I do see that mulitple threads have been opened about this and the brave team never take responsibility for it or try to fix it. they say ‘thread closed after x days of inactivity’ due to your lame answers. i don’t know why i’m even bothering to write this, i already know you won’t try to fix it.

Expected result: you would get your search results instead of brave asking you to prove you were a human.

Brave Version( check About Brave): every version for the past 2 years
Brave is up to date

Brave 1.92.144 (Official Build) (64-bit)

Additional Information: fix it. quit avoiding the issue and fix it.

Are you connected to a VPN when you see this issue?

I’m having the same issue, and yes, I do use a VPN.

Also, since my own post didn’t get any replies, I’d like to take this opportunity to confirm something: is it intentional that the top padding of Brave’s tabs is noticeably smaller than the bottom padding?

I compared screenshots of the browser UI from the Brave and Brave Origin websites. In the older Brave design, the tabs looked vertically balanced, whereas in the new Origin design, they appear to be shifted upward.

Dear

@nfkn17,

It’s perfectly understandable that this is happening to you because Google’s very aggressive and intrussive tracking and spying tools always react whenever something is suspicious and the problem is not the Brave which blocking all ads and trackers as far as possible. It wouldn’t be much different if you used a minimalist Imput.net’s Helium Browser whose blocking could be even more stronger because many pages can’t even be accessed.

And while you’re using most VPN’s, this will happen to you with every browser. Google is the default search engine at the Opera, but if you turn on their proxy, it will happen to you very soon. Of course, this also applies to Tor, and it’s no accident that the authors of the Tor Project do not have a good opinion of Google, which they recommend nowhere.

If you want faster results from Google without most ads, trackers and fingerprinting, try Startpage, which is also integrated into Brave.

Thanks for the reply! I’ve been following this thread, and I’ve already switched my search engine.

Not on VPN. and it isn’t google asking me to prove i’m human, it’s brave browser, or it appears so when the pop up occurs.

so i gave up on brave. i switched to zen, and guess what, this has not happened once. I have not changed anything else. my browser habits, my search frequency, my OS, my IP. the only thing that changed was not using brave and i haven’t had to prove i’m human when using my browser to search .i use brave for one thing right now, amazon prime video, because zen is too cheap to buy a license for DRM. once it has that, i will remove brave from my machine.

I get the same thing and I don’t use a VPN.

I’m on MacOS and I can confirm that it is the Google Search Engine on Brave Desktop. Make sure to change your default Search Engine in the Brave Settings as on install you do select set a default search engine and I previously had Google Search. Moving to another search engine resolved the verify you are human issue. Note I haven’t had to change on iOS, only the Desktop version. FYI I’m not currently using a VPN.

Brave Search uses Cloudflare service.

Cloudflare expects compliance. The actual requirements depend on which Cloudflare security product/rule the particular website operator has enabled, and Cloudflare deliberately evaluates a collection of browser and request signals rather than exposing a simple pass/fail specification.

As of Cloudflare’s current documentation (updated August 2026):

What Cloudflare expects from a browser

At the basic level, a browser encountering a Cloudflare Challenge needs to:

Execute JavaScript. Cloudflare’s challenges depend on client-side JavaScript. A browser with JavaScript disabled cannot complete them.

Accept and return the relevant cookies, particularly the cf_clearance cookie when a challenge is successfully passed. Cloudflare uses this cookie as evidence that the visitor has passed its client-side verification.

Allow Cloudflare’s challenge scripts and validation traffic to execute. Content blockers, script blockers, fingerprinting protection, and canvas/WebGL blockers can interfere.

Present a reasonably normal browser environment. Cloudflare evaluates browser-environment signals and looks for characteristics associated with automation.

Maintain a consistent network identity while solving the challenge. Cloudflare specifically says that a challenge issued from one IP and solved from another is invalid and can produce a challenge loop.

Not modify certain browser APIs in ways Cloudflare considers incompatible. Cloudflare explicitly says Challenges cannot support extensions that modify the User-Agent or Web APIs such as Canvas and WebGL.

Be a supported browser environment. Current Chrome, Firefox, Safari, and other major desktop/mobile browsers are supported; Internet Explorer, command-line clients such as curl/wget, and production browser automation frameworks are not. Heavily modified browser engines and embedded browsers have limited support.

But there’s a crucial distinction here. Cloudflare isn’t simply asking “is this a real browser?”

Its current Turnstile documentation says it performs small client-side challenges involving things such as:

  • proof-of-work,
  • proof-of-space,
  • probing Web APIs,
  • browser-quirk detection,
  • human-behavior signals,

and uses those signals to adapt the challenge to the individual browser/request.

And its JavaScript Detection system similarly gathers client-side information and records the result in cf_clearance ← a cookie that Cloudflare can set in your browser after you successfully complete a Cloudflare security challenge.

Importantly, passing JavaScript Detection does not by itself mean that Cloudflare considers the visitor completely trustworthy. Other bot-detection heuristics can still produce a suspicious result.

So there isn’t a magic set of HTTP headers you can reproduce that means “Cloudflare-compliant browser.”

Cloudflare’s documentation describes the purpose as distinguishing legitimate human visitors from automated or malicious traffic. But the mechanism is necessarily probabilistic. Cloudflare says explicitly that a challenge can be triggered by things including:

*IP threat/reputation,
*bot-detection signals,
*WAF rules configured by the site owner,
*Browser Integrity Check,
*network characteristics,
*browser configuration,
*extensions,
*VPNs/proxies, etc.

Consequently, “complies with the browser requirements” and “is accepted by Cloudflare” are not equivalent propositions.

A completely legitimate browser can fail because, for example, its privacy configuration changes the signals Cloudflare expects. Cloudflare itself acknowledges that extensions, developer-tools overrides, device emulation, VPNs/proxies, and embedded browsers can alter the signals it receives.

And Cloudflare explicitly acknowledges another important point: JavaScript Detection can fail for legitimate reasons such as network problems, ad blockers, disabled JavaScript, or native/mobile application contexts.

Almost all of that information, is from, or based upon, Cloudflare material.

Cloudflare WAF Rules

good answer. doesn’t change the circumstance though. thanks ! just proves that i was wasting my time trying to get Brave support to address the question. thanks for the tip ! why brave would force users to go through cloudflare and block searches is completely beyond me. dear brave, i’m proving i’m human by leaving your browser platform. kthxbye