Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

41–50 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#41

[flagged]

You don't think that some people simply disagree with the idea that this is bad? Or like maybe the CAPTCHA company who put out the post has an agenda here? So you want to go after engineers personally? I wonder what you've done that might warrant harassment? Look at how complicated CAPTCHAs are getting to try to be unsolvable with AI - it's a losing game. This and the WEI proposal are trying to solve a very, very rea…

But it's so easily beatable! This might be the result of good intentions (being incredibly generous), but as the article states, any bot can afford a $30 phone and the concomitant hardware as the cost of doing business and bypass this.

Also as the article states (referencing an HN comment):

> How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing QR code - you (realistically) can’t.

Susan from HR is the least of it. This is a huge vector to increase fraud, not decrease it.

How would an ethical, competent engineer argue against this?

The CAPTCHA company who put this out might have an agenda, but also since they're in the industry they might also have knowledge to impart.

We're reaching an inflection point with the oligarchies where the old ideas of "writing a blistering editorial" or "calling your congress-critter" need to be seriously questioned as useful and other non-violent methods of recapturing digital freedom need to be entertained.

Re: Google Cloud Fraud Defence is just WEI repackaged

#42
post #2

Exactly my thoughts. I am unfathomably angry and I want to contribute to any effort to dismantle Google as a company.

Yeah, same. It is hard; we start to need a collective boycott. We can all do our part, by using their products as little as possible, contribute to open alternatives (OpenStreetMap, Fediverse, Linux, Nextcloud...) and by stimulating our (non-techie!) friends and family. But it is a lot of work :(

> Yeah, same. It is hard; we start to need a collective boycott.

Feelgood slactivism. They don't care about your boycott. They finance their own alternatives because they know what makes you shut up.

Re: Google Cloud Fraud Defence is just WEI repackaged

#43

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

Yes, fewer services and infinite fraud is substantially better to me than the web being controlled by Google even more than it already is.

Re: Google Cloud Fraud Defence is just WEI repackaged

#44

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

This doesn’t even solve the problem thanks to device farms. There’s not really a solution for this short of aiming a camera at someone’s retina 24/7 plus a fully locked down hardware path. And even that would surely be compromised given enough incentives.

People are just going to have to find a new way to monetize. Maybe more things will become paywalled, or sponsored long-term like old TV shows. Again, there’s no good way to solve this, and the “solutions” on offer just contribute to the surveillance state without solving the problem.

Re: Google Cloud Fraud Defence is just WEI repackaged

#45
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

I'm amused at how thoroughly Google adopted Microsoft's playbook. Chrome supplanted Internet Explorer by embracing the open web. But then Google immediately started on extensions, and now they're trying to extinguish the open web with nonsense like Cloud Fraud Defense. All very smoothly done. I mean, people are actually _asking_ for this junk. I'm impressed.

Re: Google Cloud Fraud Defence is just WEI repackaged

#46
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

> rapidly becoming

Always has been.

Google was creating cartels like the "Open Handset Alliance" literally decades ago.

Via their control of Chrome and Search which are both monopolies, Google holds absolute authority on how websites are rendered and if websites can be found.

Re: Google Cloud Fraud Defence is just WEI repackaged

#47
post #2

Exactly my thoughts. I am unfathomably angry and I want to contribute to any effort to dismantle Google as a company.

On that topic, I would highly recommend you to switch to Kagi! Search is still their workhorse for ad revenue. Less search, less users, in addition to users now just asking chatgpt and co, will hurt them well

Wouldn’t installing an adblocker basically hurt them as much / more as I still cost them compute but don't get them that sweet ad money?

Re: Google Cloud Fraud Defence is just WEI repackaged

#48
post #11

AI use is far more prevalent now than then sadly. This kind of scheme is inevitable since compute is not free.

I disagree that this kind of scheme is inevitable. We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation. Certainly, Google can choose to avoid it. On the other hand, the AI bubble will inevitably burst, since compute is not free. I look forward to post-bubble AI.

[deleted]

Re: Google Cloud Fraud Defence is just WEI repackaged

#50

[flagged]

> Do you seriously think that if Google sees the same hardware identifier 1000s of times a day they are not going to consider that usage to be fraud?

Phones are very cheap, especially refurbished phones. Just have the phones mimic real life sleep/wake cycles and take occasional breaks. Use 25% more devices to account for the loss in uptime.

Besides, some people (often unemployed or disabled, and possibly with sleep disorders or mania) actually don’t do anything other than scroll on their phone all day and night. So you can’t rely on this as a good signal without creating even more blowback. And you really don’t want too much blowback from troubled people who have infinite free time.

Post reply on HN