Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

211–220 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#211
post #191

Earlier quoted context omitted.

[flagged]

I refer you to all my own comments about decentralized solutions, which you can see in my history. And the posts that have been flagged after amassing too many upvotes. I think that's sufficient.

My apologies then

Re: Google Cloud Fraud Defence is just WEI repackaged

#212

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

I personally think its easier to detect llm controlled browser sessions, the people deploying them are far more naive and inexperienced than traditional scrapers/crawlers. insert You wouldn't bring a 40 Petabyte Zip Bomb to School, would you? meme

Part of the problem is also that Google wants to permit crawlers to do some things but jot others.

Their announcement is full of buzzwords about "agentic" things. Detecting LLMs is one thing, but imagine the power of being able to pick which LLM browsers are permitted and which aren't!

I think Google is being too early to the party with this. Cloudflare still has CAPTCHAs to throw at the wall. There are ways other than attestation to verify that someone is a real human, but they're getting more and more annoying to real users and harder and harder to implement on a small website.

Despite the massive implications, this is a simple system that just works for the 99% of people who use Chrome or Safari or at least have access to an Android phone or iPhone somewhere. It's quick, doesn't require installing apps or creating accounts, and it just works from both the website perspective and the user perspective.

Of course when you start thinking about people with disabilities things become problematic, but when have tech companies ever really cared about that sort of thing? Inclusiveness was fun and all for a while, but the clowns the American people elected banned that sort of thing for any company considering government contracts, and big tech licked that boot like it was made of honey.

The world becomes a lot easier if you just decide to ignore all edge cases and assume customers who disagree with you didn't matter anyway. And infuriating as it may be, for companies like Google, that business model works.

Re: Google Cloud Fraud Defence is just WEI repackaged

#213
post #100

Earlier quoted context omitted.

Indeed, occasionally hammers do find nails to hit.

Strange analogy considering that RMS got to where he is precisely by finding nails to hit much, much more than occasionally, and much, much more than most hammers.

I think it hits perfectly. He espouses that almost every vendor everywhere is doing something immoral and it will inevitably be used against you. Eventually, some of these predictions come true enough for some part of his audiences.

I don't think you've made a point about his abilities. I do think you've restated his proclivities, which reinforces the basis for the quip.

Re: Google Cloud Fraud Defence is just WEI repackaged

#214
post #94

Earlier quoted context omitted.

Apple has device attestation deployed like one year before Google even proposed it: https://httptoolkit.com/blog/apple-private-access-tokens-att...

hacker news when discovering that apple deployed WEI, for ages, with beloved IT company Cloudflare, affecting hundreds of millions of users: "aww, you're sweet" hacker news when reading that google is doing the same thing for the rest of the userbase: "hello, human resources?"

I thought that cloudflare system worked on any hardware and the tokens are anonymous. Did that change at some point? If it didn't change, then yeah it should get a very different reaction!

(Edit: it looks like the new system is still private and still interlinked with the old system that lets you use any hardware? I think?)

Also I don't know how you could have missed the widespread criticism of apple and especially cloudflare on this site.

Re: Google Cloud Fraud Defence is just WEI repackaged

#216

Earlier quoted context omitted.

Do you actually think the majority of everyone else is being just as pedantic (or cares) about Google Chrome vs chromium-based? For most, for the purposes of market share (the type of "monopoly" I believe they are referring to), I think they count it as one and the same.

Do most people call Microsoft Edge or Safari "Chrome"? Are the security and privacy implications the same for Edge, Safari, and Chrome? Seems to me like they're still quite different products despite having some similar codebases!

Safari isn't based on Chromium.

Re: Google Cloud Fraud Defence is just WEI repackaged

#217

Earlier quoted context omitted.

The analogy works if you think of RMS as a nailgun.

A nailgun hitting nails? This is going nowhere..

Much as a hammer tacker hits tacks internally, so a nailgun strikes the nails within itself.

Re: Google Cloud Fraud Defence is just WEI repackaged

#218

No one should ever browse the web on a smart phone. Not joking.

and it seems Google wants to support people like you!

That entire QR barcode thing is so that you can browse the web on your laptop/desktop, and _still_ rely on smart phone's attestation, no mobile browser needed.

Re: Google Cloud Fraud Defence is just WEI repackaged

#220
post #99
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

Don't you see it closing all around you? It's not just Google. It's governments, corporations, all around the world, simultaneously. The noose is being tightened gradually, then all at once. And it's coming for all of us: https://community.qbix.com/t/increasing-state-of-surveillanc... The threats above interlock by design or convergence: Identity layer (1-5) creates the prerequisite for the others. Once identity is e…

Hell, even using cash feels like a minor form of dissent. And of course even if you leave your phone at home, your car will be scanned with ANPR wherever it goes. And if that fails, there's still your face to be tracked.
Post reply on HN