Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

1–10 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#5
post #4

The site doesn't mention this. But, are they locking down QR code auth for only safetynet authenticated devices and with mobile number verification?

Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms).

But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#8
The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652

So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future.

No mention of device integrity verification yet, but the writing is on the wall.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#9
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site.

I know, people will slavishly knuckle under, but let me dream for a few minutes.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#10
post #4

The site doesn't mention this. But, are they locking down QR code auth for only safetynet authenticated devices and with mobile number verification?

Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms). But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass…

... You... think... it would be a good thing.

Don't you...

Post reply on HN