Legitimate CAPTCHAs only ask you to solve a brief puzzle, like clicking on certain images, type in distorted text, or check a box to confirm you’re human — quick, contained tasks that stay within your browser, according to Hayden. “You should never be asked to download files, type non-alphanumeric keys on your keyboard, scan QR codes, interact with your clipboard or system tools, or open your terminal.”