Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

161–170 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#161
post #89
post #77

Earlier quoted context omitted.

>Why? What's LLM generated? How can you tell? Not the guy you're responding to, but: 1. The high number of (em) dashes is suspect, though it's unclear whether they manually replaced the em dashes or is actually human generated. 2. "One additional failure worth noting: one incident response professional in the HN thread, raised a concern that operates independently of the bot problem" feels out of place for a content…

Looks like the moderators are actively deleting comments that call out AI generated articles now. Grim. This comment will probably be deleted too.

[flagged]

Re: Google Cloud Fraud Defence is just WEI repackaged

#162
post #40

Earlier quoted context omitted.

> We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation Such as? I don't see how regulation would apply here without concrete technical solutions that enforce it. So what alternative mitigations do you have in mind?

Among many other things: Regulate the use of AI to imitate or impersonate human activity. Regulate AI crawling/scraping. Ban scraping entirely, and all models based on it. Regulate maximum model size. These wouldn't eliminate the problem, but they'd change it from "many people do this" to "this is always a malicious attack , react accordingly".

None of these proposals are enforceable in any meaningful way.

Re: Google Cloud Fraud Defence is just WEI repackaged

#163
post #36

Earlier quoted context omitted.

It should not be a "vote with your wallet" situation. It should be governments shattering that organization into appropriately sized companies.

It should have been the government providing an identity verification API, like they already do in the physical world with physical IDs. Governments dropped the ball, and so now Apple and Google get to be infrastructure.

The US government is a feckless facade, the US is a corporation run economic zone. The nice thing about being corporate run is that the rulers are unelected and unaccountable!

Re: Google Cloud Fraud Defence is just WEI repackaged

#164

No one should ever browse the web on a smart phone. Not joking.

And also don't install apps? What's left then?

A device I have no choice in owning because modern employers assume you have sometime to install an authenticator app on. That's what it is for me. Also, sadly, it's an anchor for Signal. Otherwise I don't use the stupid thing.

Re: Google Cloud Fraud Defence is just WEI repackaged

#165

Earlier quoted context omitted.

It should have been the government providing an identity verification API, like they already do in the physical world with physical IDs. Governments dropped the ball, and so now Apple and Google get to be infrastructure.

"Don't worry! I'm from the government and I'm here to ~~help~~ identify you to everyone else on the planet." That's no better, and in many ways far worse, than the corpos doing it.

Do you think identifies never need to be verified? Seems like a central function in operating an accountable society, hence birth certificates, passports, etc.

There should not be a requirement to verify identity, but if a website owner only wants to provide access to their website to people with verified identities, why is that not their right?

Re: Google Cloud Fraud Defence is just WEI repackaged

#166
post #21

Earlier quoted context omitted.

I think the better alternative to making engineers "feel uncomfortable opening their door, walking down the street" is for us to collectively ask if the solution isn't to touch more grass and rely less on the technology we've all come to blindly accept as required. I mean, I hate this QR code shit as much as anyone, but c'mon, we can and should be better - both in how we treat others, and how much we rely on this shi…

That doesn't solve a problem, that ignores a problem.

On the contrary - stepping back and asking ourselves if we've gone too far and need to do things differently would solve a litany of problems, including this.

Re: Google Cloud Fraud Defence is just WEI repackaged

#167

This is truly disturbing, and trying to sneak it in like this without public discussion is disingenous. Hopefully it will be shot down like last time - at the very least, there are surely antitrust issues here.

Last time they tried this they laundered it though an employee's personal github to distance it from google itself, then framed the proposal in the most disingenuous manner possible, as if it was something that users wanted rather than another mechanism for google to exercise control

Re: Google Cloud Fraud Defence is just WEI repackaged

#168
post #41

Earlier quoted context omitted.

But it's so easily beatable! This might be the result of good intentions (being incredibly generous), but as the article states, any bot can afford a $30 phone and the concomitant hardware as the cost of doing business and bypass this. Also as the article states (referencing an HN comment): > How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing…

You realize that $30 phone is burned the moment it's used for abuse, right? It's not $30 and then spam as much as you like. It's $30 per action per site, which makes nearly all abuse unviable.

You realize how rife abuse already is using google's infra? Do you really think google's gonna be right there, cracking down on this? This is at least as much about locking people into their infra as it is cracking down on fraud, and anybody who doesn't recognize that is at this point willfully blinding themselves.

Re: Google Cloud Fraud Defence is just WEI repackaged

#169
post #40

Earlier quoted context omitted.

> We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation Such as? I don't see how regulation would apply here without concrete technical solutions that enforce it. So what alternative mitigations do you have in mind?

Among many other things: Regulate the use of AI to imitate or impersonate human activity. Regulate AI crawling/scraping. Ban scraping entirely, and all models based on it. Regulate maximum model size. These wouldn't eliminate the problem, but they'd change it from "many people do this" to "this is always a malicious attack , react accordingly".

None of those would work without enforcement. Scams are banned, but that doesn't stop Chinese mafia from operating prison camps that run scams scamming people all around the world.

Re: Google Cloud Fraud Defence is just WEI repackaged

#170

[flagged]

I'm pretty sure that the Ai copied the $30 number from my hacker news comments. However in the USA it is true. https://www.walmart.com/ip/Straight-Talk-Motorola-Moto-g-202... (carrier locks don't matter for this usecase.) I am not sure that that storing unique device identifiers is legal in the EU.

I remembered $30 from some comment I read, but didn't look for it later. If it was yours, thank you! (def. thank you for the Wallmart link! - would you like a credit in the blogpost like a quote?
Post reply on HN