Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

251–260 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#251

Earlier quoted context omitted.

> saw this coming from miles away. Computers are better at solving CAPTCHAs than people are good point... it's interesting how Captcha was initially popularized as a reverse Turing test, but it's just variants of Proof of Work today. And it seemed clever at the time for Google to leverage this for improvement of their OCR models (it was!), and makes you wonder what utility is derived from the proven "work" today.

With the crosswalk, bike, motorcycle, stairs type of things, wasn't that just improving their training data?

Yes, for Waymo, AFAIK (I don't know for sure).

The OCR thing was earlier and used for Google Books, I think. Which is also is fitting for training data, or the motto "organize all knowledge".

At that time, this goal seemed really cool!

Re: Google Cloud Fraud Defence is just WEI repackaged

#252

Earlier quoted context omitted.

Turns out RMS has always been right. How surprising.

Turns out that identifying a problem doesn't help without a workable solution/alternative.

The whole "don't point out a problem unless you have a solution" trope is bullshit.

Re: Google Cloud Fraud Defence is just WEI repackaged

#253
post #152

Earlier quoted context omitted.

Is it just a matter of not trusting the OS? I'm trying to figure out why "smart phone" is the discriminator here.

A smart phone _could_ be legitimate and free and open, but in practice it's not. This is a constraint based on the reality of the market, not really based on what is strictly possible with the technology. I don't get too deep into this, but at a very high level, this is what I dislike about smartphones. - Touchscreen user interface is objectively worse than a mouse and keyboard. Portability is the the only benefit to…

> Touchscreen user interface is objectively worse than a mouse and keyboard

au contraire, touch screen is objectively better, and i dont buy laptops where the screen isnt a touch screen. cursors and mice and focus on laptop+mouse UXs is just horrible, and for keyboard only even worse.

the touch screen is much simpler, in that you touch or swipe on the thing, and it makes the motion in direct response to what you touched. the input is physically linked into the interaction, rather than some changing relative position.

Re: Google Cloud Fraud Defence is just WEI repackaged

#254

Earlier quoted context omitted.

It cracks me up when people say Chrome is a monopoly, because a massive amount of computing devices do not even ship with Chrome. Windows computers, Macbooks, and iPhones require users go search out and install Chrome on their own out of their own volition, shipping with entirely functional and decent browsers out of the box that they have lots of patterns to push. Even many Android phones ship with browsers other th…

> Windows computers Ship with a chromium fork called Edge

Edge isn't Chrome though, is it? Like, its not shipped by Google, it doesn't bug you to log in with a Google account, doesn't ship metrics back to Google, right?

Not quite the same thing now is it?

Re: Google Cloud Fraud Defence is just WEI repackaged

#255

Earlier quoted context omitted.

Turns out that identifying a problem doesn't help without a workable solution/alternative.

I hate this trite and the managers that say "don't bring me problems, bring me solutions" nonsense. I'm not the person to be able to fix it so the solution is make the problem known so others responsible can fix it. If I could fix it, I wouldn't be telling you about the problem. If anything, I would tell you how I fixed an issue in some stand up or other of the many meetings scheduled keeping me from working.

[deleted]

Re: Google Cloud Fraud Defence is just WEI repackaged

#256

What Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human. 1. lots of laptops have fingerprint readers & TPM2 build-in 2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly. Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and…

Those don't prove that a human is present. A FIDO2 key can be automated by electronic relay. The only way to do this involves device attestation - locking devices down and utilizing hardcoded TPM/Secure Enclave esque chips. The best we can hope for would be an open standard for those chips so that people can use them with their own X.509 certificates that lets them choose their own CA.

Re: Google Cloud Fraud Defence is just WEI repackaged

#257
Considering Google's origins and early backers, this shouldn't come as much of a shock to anyone:

https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...

The military industrial complex created the internet, and has funded many of the big players in Silicon Valley. Their goal was never an open and free internet.

Re: Google Cloud Fraud Defence is just WEI repackaged

#258

What Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human. 1. lots of laptops have fingerprint readers & TPM2 build-in 2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly. Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and…

Those don't prove that a human is present. A FIDO2 key can be automated by electronic relay. The only way to do this involves device attestation - locking devices down and utilizing hardcoded TPM/Secure Enclave esque chips. The best we can hope for would be an open standard for those chips so that people can use them with their own X.509 certificates that lets them choose their own CA.

Real hardware doesn't mean a human is present either, unfortunately. It just means that you have to spend on real devices to bypass these defences.

Re: Google Cloud Fraud Defence is just WEI repackaged

#259

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

I used to know some Americans who were on the poorer end of the spectrum, and apps that paid you for performing fitness activity and such weren't uncommon in that demographic. Not as much of a thing in Europe for some reason.

I believe the cheap Chinese pirate TV boxes that are somewhat popular in the US these days are also in botnets, which is likely how the vendors make them so cheap.

Re: Google Cloud Fraud Defence is just WEI repackaged

#260

Earlier quoted context omitted.

Strange analogy considering that RMS got to where he is precisely by finding nails to hit much, much more than occasionally, and much, much more than most hammers.

I think it hits perfectly. He espouses that almost every vendor everywhere is doing something immoral and it will inevitably be used against you. Eventually, some of these predictions come true enough for some part of his audiences. I don't think you've made a point about his abilities. I do think you've restated his proclivities, which reinforces the basis for the quip.

This is particularly uncharitable to someone that saw around many corners and was articulate enough to warn us about them in advance.

There's a reason there's a subreddit called "Stallman Was Right", and it's not that he was shotgun blasting opinions and landed a few of them. It's because he has a systemic understanding of the incentives our system sets up and is able to project decades into the future about how those incentives will play out.

Post reply on HN