Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

61–70 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#61

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

> Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity?

A combination of "regulate AI" and "The optimal amount of fraud is not zero". https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...

Re: Google Cloud Fraud Defence is just WEI repackaged

#63

Earlier quoted context omitted.

You don't think that some people simply disagree with the idea that this is bad? Or like maybe the CAPTCHA company who put out the post has an agenda here? So you want to go after engineers personally? I wonder what you've done that might warrant harassment? Look at how complicated CAPTCHAs are getting to try to be unsolvable with AI - it's a losing game. This and the WEI proposal are trying to solve a very, very rea…

> You don't think that some people simply disagree with the idea that this is bad? Some people think women shouldn’t be allowed to vote, not all opinions are created equal.

You can't say not all opinions are equal and everyone should have an equal vote.

Are some ideas worth more than others should some people's votes count more than others? You can't have both.

Re: Google Cloud Fraud Defence is just WEI repackaged

#64
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

I'm amused at how thoroughly Google adopted Microsoft's playbook. Chrome supplanted Internet Explorer by embracing the open web. But then Google immediately started on extensions, and now they're trying to extinguish the open web with nonsense like Cloud Fraud Defense. All very smoothly done. I mean, people are actually _asking_ for this junk. I'm impressed.

No they didn't. Firefox unseated Internet Explorer. Chrome then got big by putting its installer right on the Google homepage and harassing users to install it. And they had it bundled with other software, and would install as a user so that locked down computers could still run it. They absolutely did not win by embracing open standards.

Re: Google Cloud Fraud Defence is just WEI repackaged

#65
post #36

Earlier quoted context omitted.

Yeah, same. It is hard; we start to need a collective boycott. We can all do our part, by using their products as little as possible, contribute to open alternatives (OpenStreetMap, Fediverse, Linux, Nextcloud...) and by stimulating our (non-techie!) friends and family. But it is a lot of work :(

It should not be a "vote with your wallet" situation. It should be governments shattering that organization into appropriately sized companies.

These days every time a government as much as thinks of imponging on a supranational corporation's right to do whatever the hell it pleases you'll hear no end of cries ranging from "overregulation" to "tyranny".

For an example, see EU's GDPR, DMA etc.

Re: Google Cloud Fraud Defence is just WEI repackaged

#66

[flagged]

You don't think that some people simply disagree with the idea that this is bad? Or like maybe the CAPTCHA company who put out the post has an agenda here? So you want to go after engineers personally? I wonder what you've done that might warrant harassment? Look at how complicated CAPTCHAs are getting to try to be unsolvable with AI - it's a losing game. This and the WEI proposal are trying to solve a very, very rea…

> Or like maybe the CAPTCHA company who put out the post has an agenda here?

That captcha company is not trying to push spyware onto my device and punish me for daring to remove it. Google is.

> Look at how complicated CAPTCHAs are getting to try to be unsolvable with AI - it's a losing game.

So don't play. Even cloudflare had a better idea - don't block, just demand payment.

Re: Google Cloud Fraud Defence is just WEI repackaged

#67
As much as I hate whatever google's doing, this article has some issues:

>For operations that need Play Integrity attestation specifically, a compliant Android device costs approximately $30 at current market prices

This assumes the logic on google's side is something like `if(attestationResult == "success") allow()`, but it's not hard to imagine the device type being factored into some sort of fraud score. For instance, expensive devices might have a lower fraud score than cheaper devices, to deter buying a bunch of cheap devices. They might also analyze the device mix for a given site, so if thousands of Chinese phones suddenly start signing up for Anne's Muffin Shop, those will get a higher fraud score.

>Firefox for Android does not appear in Google’s stated browser support list for Fraud Defense.

The browser only needs to show a QR code, so if you're on firefox mobile they'll either open a deeplink to google play services on the phone itself, or show a qr code.

>One human solving a single challenge pays a negligible cost. A bot farm running concurrent sessions faces exponential compute costs with each additional attempt - and AI agents, which consume GPU cycles to operate, face identical penalties regardless of how sophisticated their reasoning is.

PoW for bot protection basically never caught on because javascript performance is poor, and human time is worth more than a computer's time. An attacker doesn't care if some server has to wait 10s to solve a PoW challenge, but a human would. An 8-core server costs 10 cents per hour on hetzner. Even if you assume everyone has a 8-core desktop-class CPU at their disposal (ie. no mobile devices), a 6 minute challenge would cost an attacker a penny. On the other hand how much do you think the average person values 6 minutes of their time?

Re: Google Cloud Fraud Defence is just WEI repackaged

#68

[flagged]

one person's villain is another person's hero. I imagine if they would be named and shamed, they would get huge contracts in companies like oracle.

Good luck getting a huge contract with Oracle. Facebook.. yes.

Re: Google Cloud Fraud Defence is just WEI repackaged

#69
post #21

[flagged]

I think the better alternative to making engineers "feel uncomfortable opening their door, walking down the street" is for us to collectively ask if the solution isn't to touch more grass and rely less on the technology we've all come to blindly accept as required. I mean, I hate this QR code shit as much as anyone, but c'mon, we can and should be better - both in how we treat others, and how much we rely on this shi…

That doesn't solve a problem, that ignores a problem.

Re: Google Cloud Fraud Defence is just WEI repackaged

#70

[flagged]

I'm pretty sure that the Ai copied the $30 number from my hacker news comments. However in the USA it is true. https://www.walmart.com/ip/Straight-Talk-Motorola-Moto-g-202... (carrier locks don't matter for this usecase.) I am not sure that that storing unique device identifiers is legal in the EU.
Post reply on HN