I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…
Google Cloud fraud defense, the next evolution of reCAPTCHA
201–210 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#202Earlier quoted context omitted.
This is going to make my grapheneos journey a bit more exciting. How wild to force users through an official google identification for web browsing. Does the iPhone recaptcha app force you to login with a Google account? Seems we didn't need ID verification for the web to lose all anonymity.
I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#203Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#204Earlier quoted context omitted.
You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)
They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying
(Also if you want to talk annoying payments don't get me started on how insane it is that the US still requires me to hand over a physical card at most restaurants to take over to their register... sorry I just can't help but get annoyed by this lol)
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#205Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#206The bulletpoint as-is just says:
> AI-resistant challenge: As we identify potentially fraudulent behavior from agents, we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop using the new QR code-based challenge. This AI-resistant mitigation challenge to prove human presence is designed to make automated fraud economically unviable.
Followed by
> Existing reCAPTCHA customers are automatically Fraud Defense customers, with no migration required, no action needed, and no change to pricing. Your existing site keys and integrations remain exactly as they are today.
It is probably me being a literal reader but "we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop" feels like it can be read as "Good news: by using reCAPTCHA, we're now interfering with agents that can solve the regular challenges" or "there's now a flag the application developer can set". This is the difference between me swapping off reCAPTCHA ASAP or just editing my configuration. I have to imagine someone somewhere anticipated the kind of reactions a number of us are collectively feeling (I too don't want to use my phone to browse the web more than I already do) and it feels irresponsible to publish a feature announcement without covering basic information like this for site administrators. Maybe they thought the second line about existing reCAPTCHA customers being moved over clears this up, but "Your existing ... integrations remain exactly as they are today" feels like again, literally, you won't have this new attestation requirement being presented to your users... but then why am I Fraud Defense customer!
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#207Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#208Earlier quoted context omitted.
I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…
But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#209I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…
Whats to stop malicious actors (bad extensions, compromised cdn, etc.) from painting over the qr code or injecting their own? This is so incredibly terrible.
As a side note though, I recently have tried to turn CSP on a website I run and the amount of garbage I see in the reports is astonishing. There's some noise from things like OpenDNS intercepting YouTube or Social embeds for people using the work-friendly or family-friendly options, but the sheer amount of things attempting to phone home to random URLs and random extension scripts injecting ads into the site would astonish you. My mental model of "toolbar hell" from the Windows XP days being gone has completely shattered.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#210Hmm, that QR code workflow doesn't look very accessible. Can we preemptively ADA this thing out of existence somehow?