Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

41–50 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#42
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I've been saying for years that it does not make sense to browse the web on a smartphone. Eventually things will get bad enough that people will agree with me.

Smartphone is just a small computer. I don't see hiw what you say makes sense.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#43

Earlier quoted context omitted.

Chrome does...

Interestingly, only on desktop/Android and not iOS it seems.

Chrome on iOS uses WebKit, so that makes sense.

(*I think in the EU, iOS Chrome can use Blink, but I am not sure if it actually does.)

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#46
post #31

Earlier quoted context omitted.

Bluetooth is generally used to prove that the two devices are co-located, which makes it more complex to do your proposed kind of deployment at-scale. Bespoke solutions could perhaps work around for some smaller number of devices, this QR code layer by itself isn't intended to stop 100% of workarounds.

No browser supports Bluetooth.

These passkey QR codes don't need to use Web Bluetooth API, because they utilize the WebAuthn API. The website itself isn't given access to the bluetooth, the task is handed off to the browser, which as a native application, can access bluetooth and abstracts the bluetooth away.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#47

Earlier quoted context omitted.

Which would be meaningful if phones weren't remotely controllable. So the net effect is every AI agent will also have and connect to a physical phone.

The attestation will include a unique ID of the phone, so that if you get banned you have to keep buying new phones and keep paying money to Google. Google won't stop this because it makes them money. And the official Google OS just won't feature remote-control software.

There's also remote control hardware (a printer-like device can operate a touchscreen). But the first point stands, yes. Be it a phone or another hardware attestation device, they and Apple will be giving "I am human, let me participate in society" checkmarks out, directly or indirectly for money

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#49

Earlier quoted context omitted.

... You... think... it would be a good thing. Don't you...

I do. It has downsides of course, but what's the alternative at this point?

I suspect that the HN crowd is somehow insulated from the river of crap and fraud that is the internet experience for a majority of the population.
Post reply on HN