Earlier quoted context omitted.
You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)
They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying
Google Cloud fraud defense, the next evolution of reCAPTCHA
121–130 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#122Earlier quoted context omitted.
I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…
One of them pretends to hold elections.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#123Earlier quoted context omitted.
99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.
> press win+R ctrl+V LOL is this real? I guess yes, because yesterday ReCaptcha asked me to screenshot a QR-code with the mobilephone :-D
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#124Earlier quoted context omitted.
Yeah, this is going to turn into another malware vector, isn't it?
Discord has a feature where you can log into your account on your PC by scanning a code on your phone. So does Binance.
Not about attesting to Google that you have a proper smartphone as a proxy for your humanity, like this thing.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#125The QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.
Scan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit I must not be the first one to think of this, right? Right???
Both (Google/Apple) need a much higher level of certification for anything to be allowed to be prompted to install. Either you're already big (and can easily afford to pay for some human time to verify), or you're a manufacturer selling something that has an associated app (again, which implies you're reasonably big and can afford to pay for verification.)
You're neither? Get lost. Somebody types in the name of the app, fine, but the user must find it.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#126Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#127The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#128I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…
Not that I like this thing at all. But using a QR isn’t exactly why it sucks.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#129The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.
I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#130The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.
I've seen multiple people break botguard (the obfuscation used by recapcha) within the last year when before it was considered a huge technical envour.
Devices like phones don't have this issue since Google owns the client attestation end to end and can fingerprint you without the risk of receiving spoofed values.