Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

71–80 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#71

Earlier quoted context omitted.

I've been saying for years that it does not make sense to browse the web on a smartphone. Eventually things will get bad enough that people will agree with me.

Smartphone is just a small computer. I don't see hiw what you say makes sense.

It's a small computer that I don't really control with a horrible UI, horrible privacy, and nothing but perverse incentives. ("download the app!")

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#72

How are people stopping bots reliably?

The first step is to write down why you are stopping bots and which bots you are stopping. If an LLM is buying things from your web store, that's good. You are making money on that, and you shouldn't stop it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#73
post #9

Earlier quoted context omitted.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

I have blocked it for years with ublock origin, if a site doesn't work, ctrl-w. Nowadays i cannot even use google search because of this, any search will trigger a captcha, hilarious (atleast on chromium-based browsers, firefox lets me get a page or two).

Ditch Google Search as well then, use something like SearXNG or another meta-search engine. You'll get more representative results, no tracking and no captchas. Sometimes some of the engines may return captchas but they're kept from the search results, i.e. those engines don't get used for the query. You can run your own instance of SearXNG or one of the alternatives or use one of the available public instances, your choice. The fewer direct interactions with the likes of Google/Apple/Microsoft/etc. the better.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#74

Earlier quoted context omitted.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

They will do exactly as it says while also ceaselessly complaining, completely unable to connect their choice to use a website with the pain of using that website. There's some sort of serious issue with learned helplessness or something

It's almost like some people aren't IT hobbyists.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#75
post #22

Earlier quoted context omitted.

Yeah, this is going to turn into another malware vector, isn't it?

Discord has a feature where you can log into your account on your PC by scanning a code on your phone. So does Binance.

So does Signal.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#76
post #9
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

The thing is even a contact form without something like reCaptcha is doomed on today's web: spam all day.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#78

Why can't an AI scan the QR code? Just fire up an emulator if necessary

The app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.

So openclaw or whatever future software will run or control unmodified google os devices.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#80
post #9

Earlier quoted context omitted.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

> press win+R ctrl+V

LOL is this real?

I guess yes, because yesterday ReCaptcha asked me to screenshot a QR-code with the mobilephone :-D

Post reply on HN