Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

11–20 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#11
post #9
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#12
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

This is going to make my grapheneos journey a bit more exciting. How wild to force users through an official google identification for web browsing.

Does the iPhone recaptcha app force you to login with a Google account? Seems we didn't need ID verification for the web to lose all anonymity.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#13
post #6

Google building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.

They're expecting everyone to whitelist Google agents because Google has the market share for people to complain if Google agents don't work.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#15
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I've been saying for years that it does not make sense to browse the web on a smartphone. Eventually things will get bad enough that people will agree with me.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#16

Why can't an AI scan the QR code? Just fire up an emulator if necessary

The app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.

I know that's the final destination, but I didn't see that listed in the requirements page linked above. Any proof of this affecting the current implementation?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#17
post #9

Earlier quoted context omitted.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

They will do exactly as it says while also ceaselessly complaining, completely unable to connect their choice to use a website with the pain of using that website.

There's some sort of serious issue with learned helplessness or something

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#18
post #6

Google building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.

With the apparent competence that built Gemini, I have zero faith in Google building or doing anything that works anymore.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#19
Google and the reCAPTCHA network aren't even that good with fraud prevention. You would think being literally omniscient over the whole internet would make it trivial to catch account takeovers, and Gmail has a proven track record at resisting account takeover, but when we tried to integrate their fraud signals, they were worthless, worse than the rest of the industry, worse than our homegrown trash from a decade ago.

Because Google doesn't actually care about preventing fraud, they just want the data you feed them and the fraud feedback you provide. It's all take, no mutual business.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#20

Why can't an AI scan the QR code? Just fire up an emulator if necessary

The app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.

Which would be meaningful if phones weren't remotely controllable.

So the net effect is every AI agent will also have and connect to a physical phone.

Post reply on HN