Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

71–80 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#71

I think this is the third HN link I've clicked on in a row that leads to an LLM-generated article. I'm not opposed to AI, but I'm tired of seeing it quietly substituted for human thought and expression.

I'm seeing this stance a lot "this is obviously AI generated" Why? What's LLM generated? How can you tell? To me what's obvious is that our trust system is already breaking down. Commenters accusing each other of being AIs is also another example of this.

The entire article is just one long stream of short, punchy, declarative sentences. The latest Claude models are notorious for writing like this.

There's also a few cookie-cutter patterns that should immediately jump out at you if you're at all familiar with AI writing, such as:

> No hardware identifier is transmitted. No attestation is required. No certification layer determines who may participate. User privacy is structurally preserved, not promised.

> Google Cloud Fraud Defense is not a reCAPTCHA update. The QR code is the visible mechanism, but device attestation is the real product.

Re: Google Cloud Fraud Defence is just WEI repackaged

#72

[flagged]

These are private actors. It's not acceptable to harass people for building things that are lawful but that you don't like.

If you don't like this functionality, participate in democracy and work with your representatives to make it unlawful. But be prepared to humbly lose if the majority disagrees with you.

You're not, however, entitled to a "heckler's veto."

Re: Google Cloud Fraud Defence is just WEI repackaged

#73

I think this is the third HN link I've clicked on in a row that leads to an LLM-generated article. I'm not opposed to AI, but I'm tired of seeing it quietly substituted for human thought and expression.

I'm seeing this stance a lot "this is obviously AI generated" Why? What's LLM generated? How can you tell? To me what's obvious is that our trust system is already breaking down. Commenters accusing each other of being AIs is also another example of this.

The choppy language is the biggest trigger for me. Examples:

* "With Fraud Defense, there was no process to respond to. The product launched. The requirements page went live."

* "That is not a technical limitation waiting to be engineered around. It is the mechanism."

* "The defeat is mechanical. Bot operators point a camera at a screen, a trivial automation with off-the-shelf hardware."

I could be wrong, of course. Maybe humans are starting to write like LLM's, or maybe it's just confirmation bias on my part.

Re: Google Cloud Fraud Defence is just WEI repackaged

#74

[flagged]

It is particularly funny because this is content marketing for a computational proof of work "captcha". Those are pure snakeoil, with economics that are probably at least four orders of magnitude more favorable to the abusers than this attestation would be.

Re: Google Cloud Fraud Defence is just WEI repackaged

#75
post #40
post #11

Earlier quoted context omitted.

I disagree that this kind of scheme is inevitable. We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation. Certainly, Google can choose to avoid it. On the other hand, the AI bubble will inevitably burst, since compute is not free. I look forward to post-bubble AI.

> We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation Such as? I don't see how regulation would apply here without concrete technical solutions that enforce it. So what alternative mitigations do you have in mind?

Among many other things: Regulate the use of AI to imitate or impersonate human activity. Regulate AI crawling/scraping. Ban scraping entirely, and all models based on it. Regulate maximum model size.

These wouldn't eliminate the problem, but they'd change it from "many people do this" to "this is always a malicious attack, react accordingly".

Re: Google Cloud Fraud Defence is just WEI repackaged

#76
post #54

Maybe a dumb question, but how is this suppose to work for iphone users? They wont have google play, and it seems like android/google play is required here? There is no way they would cut out such a huge chunk of the market.

The claim is that an iPad/iPhone will also work. Not that that makes it acceptable; if anything, it's worse, because if it were Google Play only it'd be more obvious how unacceptable it is, whereas catering to the duopoly makes it less obvious how much it excludes people and builds a reliance on proprietary systems.

One company can soon dictate who can enter the websites. And only two commercial operating systems are viable in the world after this change. Not nice.

Re: Google Cloud Fraud Defence is just WEI repackaged

#77

I think this is the third HN link I've clicked on in a row that leads to an LLM-generated article. I'm not opposed to AI, but I'm tired of seeing it quietly substituted for human thought and expression.

I'm seeing this stance a lot "this is obviously AI generated" Why? What's LLM generated? How can you tell? To me what's obvious is that our trust system is already breaking down. Commenters accusing each other of being AIs is also another example of this.

>Why? What's LLM generated? How can you tell?

Not the guy you're responding to, but:

1. The high number of (em) dashes is suspect, though it's unclear whether they manually replaced the em dashes or is actually human generated.

2. "One additional failure worth noting: one incident response professional in the HN thread, raised a concern that operates independently of the bot problem" feels out of place for a content marketing piece. HN isn't popular enough to be invoked as a source, and referencing it as "the HN thread" seems even weirder, as if the author prompted "write a piece about how google cloud defense sucks, here are some sources: ..."

3. This passage is also suspect because it follows the chained negation pattern, though it's n=1

>No hardware identifier is transmitted. No attestation is required. No certification layer determines who may participate.

edit:

I also noticed there are 2 other comments that are flagged/dead expressing their reasons.

Re: Google Cloud Fraud Defence is just WEI repackaged

#78
post #41

Earlier quoted context omitted.

You don't think that some people simply disagree with the idea that this is bad? Or like maybe the CAPTCHA company who put out the post has an agenda here? So you want to go after engineers personally? I wonder what you've done that might warrant harassment? Look at how complicated CAPTCHAs are getting to try to be unsolvable with AI - it's a losing game. This and the WEI proposal are trying to solve a very, very rea…

But it's so easily beatable! This might be the result of good intentions (being incredibly generous), but as the article states, any bot can afford a $30 phone and the concomitant hardware as the cost of doing business and bypass this. Also as the article states (referencing an HN comment): > How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing…

You realize that $30 phone is burned the moment it's used for abuse, right? It's not $30 and then spam as much as you like. It's $30 per action per site, which makes nearly all abuse unviable.

Re: Google Cloud Fraud Defence is just WEI repackaged

#79

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

I don't know which activity you're referring to, but why are you trying to discriminate between humans and bots? Because bots don't pay? So demand payment.. Demand like payment per account creation, then set appropriate rate limits per account.
Post reply on HN