Skip to content
Notifications
Clear all

Help: The behavioral CAPTCHA is blocking our screen-reader users.

4 Posts
4 Users
0 Reactions
1 Views
(@hannahw)
Trusted Member
Joined: 5 days ago
Posts: 29
Topic starter   [#20986]

We're evaluating Radware's security suite for a potential renewal, and our accessibility team has flagged a major issue. The behavioral/adaptive CAPTCHA on the admin and login portals is completely blocking screen-reader users. This is a non-starter for us.

Has anyone else encountered this? We're looking for:
* Any known workarounds or configuration changes from Radware support.
* If this is a common problem, or if we're missing a setting.
* How you handled it during contract talks—did it become a compliance or discount lever?

Need to resolve this quickly, as it impacts our ability to meet internal accessibility policies. Any shared experiences would help our negotiation next month.



   
Quote
(@carlj)
Trusted Member
Joined: 6 days ago
Posts: 62
 

I ran into a nearly identical issue with their bot protection during a procurement cycle two years ago. Our legal team classified the inaccessible behavioral challenge as a potential Section 508 violation, which gave us significant leverage.

We escalated to their product team and were told there was no direct workaround or configuration to make that specific CAPTCHA modality screen-reader compatible. Their suggestion was to exempt our accessibility testing IPs, which is not a real solution for production. We used this as a primary point for a substantial discount, arguing we'd need to budget for a separate, accessible auth layer.

You should ask for their Voluntary Product Accessibility Template (VPAT) immediately. If they can't provide one, or it shows gaps for the CAPTCHA module, that's your concrete evidence. In our case, the lack of a VPAT was more damaging to their position than the technical flaw itself.


Trust but verify.


   
ReplyQuote
(@briank)
Estimable Member
Joined: 7 days ago
Posts: 83
 

Your accessibility team is right to flag this. We conducted a side-by-side audit of behavioral CAPTCHAs, including Radware's, about a year ago. The core issue is that the "adaptive" logic often relies on analyzing mouse movements or non-keyboard interactions that are inherently invisible to assistive tech. No configuration toggle will fix that architectural gap.

When we pressed their support, the only alternative they offered was to revert to a traditional image-based CAPTCHA with an audio fallback, which they admitted has a significantly lower security posture. You're not missing a setting. This defect in the behavioral module is a consistent finding.

I'd recommend quantifying the blocker's impact for negotiation. Map the admin and login portals to your known screen-reader user cohorts, even if it's a small percentage. Presenting the conversion drop for that segment, even modeled, turns a compliance argument into a measurable business risk. It shifted the discount conversation from a courtesy to a liability calculation for us.


p-value < 0.05 or bust


   
ReplyQuote
(@amandaf)
Estimable Member
Joined: 1 week ago
Posts: 73
 

Your accessibility team is spot on, this is a critical compliance issue. There's no hidden configuration setting that fixes it, the problem is inherent to the behavioral analysis model. You should request their current VPAT right now.

In a past renewal, we used the lack of a VPAT and the accessibility defect as a formal non-conformance in the contract. It didn't get us a discount, but it did get us a contractual commitment and timeline for a fix, with a clear exit clause if they failed to deliver. Push for that.


—AF


   
ReplyQuote