How Much Time Do You Spend Proving You’re Human?
A personal audit of password resets, 2FA codes, CAPTCHAs, and device checks — and how much of it is actually avoidable.
The audit starts with one slider: how many more years you expect to stay digitally active. Forty years is the default, but the number only matters because everything below scales with it — a small monthly habit, stretched across decades, is the whole point of this page.
Next comes the password reset question, with a Measured / Estimated toggle. Pick Estimated and the field fills with the industry default, 3 minutes 46 seconds per reset, based on ExpressVPN’s 2022 survey of 8,000 people across the US, UK, France, and Germany. Pick Measured and the field clears — type your own number if you know it, or leave it blank and the calculation quietly falls back to the same default rather than treating a blank field as zero seconds.
Two-factor prompts and CAPTCHAs are entered together, since both interrupt the same kind of moment: you’re already logged in, or trying to be, and something asks you to prove it again. The CAPTCHA default, 32 seconds, comes from Cloudflare’s own 2021 measurement of how long a typical challenge takes to solve. There’s no equally solid public figure for personal 2FA frequency, so that default is marked Estimated and left fully editable — better an honest guess you can correct than a fake precision.
The last step covers device and location verification — the “we don’t recognize this device” emails and codes. It’s the least documented category of the four, so its defaults are the roughest and most clearly labeled as such.
The result doesn’t collapse into a single score. It opens with one number: total hours over your chosen horizon, translated into workdays and full weekends so the scale is easy to hold in your head. Below that, four bars show exactly where the time goes each year — for someone resetting a password twice a month at the default rate, facing two 2FA prompts a day, one CAPTCHA a week, and one device check a month, that’s roughly 90 minutes a year on resets and about 3 hours on 2FA, adding up to just under 5.5 hours a year, or 9 days over 40 years.
Underneath the bars is a second, more important split, grouped by what the friction actually protects rather than by how annoying it feels. Password resets and CAPTCHAs land on one side: a reset only exists because of your own forgotten credentials, and a CAPTCHA protects the site from bots, not your account from anyone. Two-factor prompts and device verification land on the other side, together, because they do the same job — both stand between an attacker and your account, just triggered differently. The bar doesn’t tell you either side is wrong. It just tells you honestly which minutes bought you protection and which didn’t.
The last interactive element simulates switching to passkeys. Toggle it on and only the password-reset bar changes — it’s struck through and fades, because there’s no password left to forget. Two-factor, CAPTCHA, and device checks stay exactly where they were, since passkeys don’t touch those mechanisms. According to the FIDO Alliance’s Passkey Index (October 2025), passkey sign-ins succeed 93% of the time versus 63% for passwords — the toggle here shows what that reliability is actually worth to you, in hours, without recommending any specific app or service.
Copy Summary saves a plain-text breakdown to your clipboard — every number, no interpretation attached. Reset clears everything back to the defaults above.