Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

241–250 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#241

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either

Do you think this won’t also be bypassed, by bribing people to scan QR codes and spoofing location etc.?

Re: Google Cloud Fraud Defence is just WEI repackaged

#242

Earlier quoted context omitted.

If a user is openly going out of their way to go and install a competitor's product despite a perfectly serviceable version coming by default, how can the the one being sought out be seen as a monopoly? The competition came pre-installed! How did the user manage to install Chrome on Windows if Chrome is a monopoly, the only serviceable browser around? They copy the source code from a magazine or something? Get a flop…

Whatever your definition of monopoly is, it's wrong. The threshold is not 100% market share. If that was the threshold no monopoly has ever existed.

> Whatever your definition of monopoly is, it's wrong

Ok, so enlighten me which standard of monopoly they're so obviously breaking?

> The threshold is not 100% market share.

I never once said so

I'm not arguing it requires 100% marketshare. I'm just pointing out there are tons of workable competitors out there, in fact one has to use a functional and fully featured competitors product to go and install Chrome on most platforms out there.

How can one claim Chrome is a monoply when there are tons of competitors out there which work just fine, and for most users their computers came with the competitors products?

Please, do enlighten me, how is Chrome a monopoly?

Re: Google Cloud Fraud Defence is just WEI repackaged

#243

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

I mean depending on the cost, Google is guaranteed to lose the battle, like gaming anticheat: there are tools that do parsing of the image on screen and send input as a usb device, there is absolutely nothing to detect.

Doing that for a webpage seems way easier than s videogame

Re: Google Cloud Fraud Defence is just WEI repackaged

#245
> The defeat is mechanical. Bot operators point a camera at a screen, a trivial automation with off-the-shelf hardware. For operations that need Play Integrity attestation specifically, a compliant Android device costs approximately $30 ($29.88 in Wallmart to be precise) - for a professional bot farm, which purchases devices in bulk, this is the fixed cost without material disruption to operations.

That's $30 per account, not one time. Because of the following:

> Device attestation does not just gate access - it produces attribution. A device with a stable hardware identity creates a persistent identifier that crosses sessions, browsers, and private browsing modes.

If you put all your bot accounts on one device, they all get banned at once. So fraudsters have to spread their accounts across multiple devices and replace them when they inevitably get banned. That's the reason for all the spying, attestation, and lockdown bullshit behind Google Cloud Fraud Defense. It is far easier to ban fraudsters if you just let the Maoists run the Risk Department.

The author proposes an alternative solution: proof-of-work. And, yes, there are use cases for that, such as Anubis. Google might even want to consider a proof-of-work option in certain scenarios. But there is no scenario in which someone's phone deliberately burns $30 worth of compute - perhaps a quarter of the user's battery - and the user still has a good onboarding experience. Most of your actual users are not going to be able to burn compute as efficiently as fraudsters, either - so maybe you have to burn the whole battery on a phone to cost a fraudster $30. Proof-of-work is, strictly speaking, anti-egalitarian and anti-democratic. "One CPU, One Vote" is less useful than you think when you realize fraudsters have the money to just buy lots of CPUs to always win[0].

Every Risk Department eventually reinvents arbitrary and capricious punishment. When you have no legal authority to prosecute crime, you rely entirely upon your freedom of association and ban people with a hair trigger. It's the only thing that works. Personally, I'd rather live in the world where governments actually took fraud seriously and corporations didn't have to do this, but for right now, GCFD is at least less onerous than WEI in the sense that WEI was going to lock down all browsers. GCFD just means I have to keep a Google-approved phone around to scan a QR code every once in a while.

[0] I'm not mentioning the massive waste problem proof-of-work creates, because obviously attestation will also produce waste. Actually, if anything, the fraudsters will probably wind up dumping all their banned devices on the used market and ruin it.

Re: Google Cloud Fraud Defence is just WEI repackaged

#246
What Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human.

1. lots of laptops have fingerprint readers & TPM2 build-in

2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly.

Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and both provide some level of proof of work / require human interaction, without revealing the identity of the end-user.

Why not use or standardise these? because there's no benefit to Google of course.

Re: Google Cloud Fraud Defence is just WEI repackaged

#248

What Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human. 1. lots of laptops have fingerprint readers & TPM2 build-in 2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly. Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and…

neither 1 nor 2 can prove you're a human. sorry

Re: Google Cloud Fraud Defence is just WEI repackaged

#249

Earlier quoted context omitted.

> saw this coming from miles away. Computers are better at solving CAPTCHAs than people are good point... it's interesting how Captcha was initially popularized as a reverse Turing test, but it's just variants of Proof of Work today. And it seemed clever at the time for Google to leverage this for improvement of their OCR models (it was!), and makes you wonder what utility is derived from the proven "work" today.

CAPTCHAs were designed as a type of Turing Test, not a reverse Turing Test. It’s not surprising that the effectiveness of these weaker variants has collapsed, given that AI can now pass the real Turing Test.

LLM’s can still only pass limited Touring Tests. The longer the interaction the worse they do. Which of course means you can easily create an experiment they successfully pass, but just as easily you can create an experiment where they fail.

CAPTCHAs are nearly useless because of how little you need to pay humans to solve them.

Re: Google Cloud Fraud Defence is just WEI repackaged

#250

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

I'm pretty sure it's one of the revenue models for those free tv/movie boxes. You can even see them at best buy. Absurd.
Post reply on HN