Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

31–40 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#31

Why can't an AI scan the QR code? Just fire up an emulator if necessary

Bluetooth is generally used to prove that the two devices are co-located, which makes it more complex to do your proposed kind of deployment at-scale. Bespoke solutions could perhaps work around for some smaller number of devices, this QR code layer by itself isn't intended to stop 100% of workarounds.

No browser supports Bluetooth.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#32
post #3

The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.

Where is this specified? I don't see that in TFA.

I think they are jumping ahead but it does seem like a logical conclusion. Would tie in nicely with the online ID verification stuff popping up everywhere.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#35
post #31

Earlier quoted context omitted.

Bluetooth is generally used to prove that the two devices are co-located, which makes it more complex to do your proposed kind of deployment at-scale. Bespoke solutions could perhaps work around for some smaller number of devices, this QR code layer by itself isn't intended to stop 100% of workarounds.

No browser supports Bluetooth.

Chrome does...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#36
post #6

Google building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.

It’s the same thing with Sam Altman and Worldcoin: create the problem, then sell people the solution (which also just so happens to shred more privacy). Play both sides and profit; it’s great work if you can get it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#38

Earlier quoted context omitted.

Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms). But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass…

... You... think... it would be a good thing. Don't you...

I do. It has downsides of course, but what's the alternative at this point?
Post reply on HN