Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

271–280 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#271

Earlier quoted context omitted.

what alternative to WEI do you propose? it solves a bajillion Internet-existential problems. it is definitely a crisis. the bot problem is at least as serious as facebook, gmail serving without https. the fact that this kind of comment gets downvoted proves my point. so what if you personally don't like WEI? it doesn't mean the problems aren't real... that aside, i don't know how people say stuff like "malicious forc…

Bombing every AI data center on Earth would also solve the Internet-existential problems we're facing. But that solution is beyond the pale of course, instead it's incumbent on me to prove to you that panopticon surveillance of every living human being from now until the Sun consumes us is not a reasonable solution to "bots use the Internet".

Ok so what's your solution to the bot problem? I don't have one, unless you count the option of websites not being free-as-in-beer anymore.

Re: Google Cloud Fraud Defence is just WEI repackaged

#272

Earlier quoted context omitted.

What is his solution to combatting botnets at scale?

His solution is don't. Why would you? In fact, if you don't block the script that's running on one computer, the script operator won't need to run it on a botnet. I don't know RMS's solution to spam or DDoS which are the real problems.

> Why would you?

Because controlling a large number of accounts can allow you to manipulate the algorithms on Web2.0 websites. For example, this one. If you don’t combat spammers the front page quickly gets filled up with garbage.

Re: Google Cloud Fraud Defence is just WEI repackaged

#273
post #94

Earlier quoted context omitted.

Apple has device attestation deployed like one year before Google even proposed it: https://httptoolkit.com/blog/apple-private-access-tokens-att...

hacker news when discovering that apple deployed WEI, for ages, with beloved IT company Cloudflare, affecting hundreds of millions of users: "aww, you're sweet" hacker news when reading that google is doing the same thing for the rest of the userbase: "hello, human resources?"

Were you attempting to give us an example of the Goombah Fallacy? Because this is a picture perfect one.

Re: Google Cloud Fraud Defence is just WEI repackaged

#274

From "Don't be evil" to building the largest, most invasive, surveillance operation the world has ever seen. That was true before this, but this indicates nothing will ever be enough. Google will always want to track more of everyone's activity online, and will use every tool at their disposal to do it.

> Google

It's not Google, it's someone. A person came up with this idea and is pushing it through. We should stop treating corporations as some abstract entity instead of a group of sick people making these kinds of decisions.

Re: Google Cloud Fraud Defence is just WEI repackaged

#275

I think this is the third HN link I've clicked on in a row that leads to an LLM-generated article. I'm not opposed to AI, but I'm tired of seeing it quietly substituted for human thought and expression.

I'm seeing this stance a lot "this is obviously AI generated" Why? What's LLM generated? How can you tell? To me what's obvious is that our trust system is already breaking down. Commenters accusing each other of being AIs is also another example of this.

"this is AI" is the new "This is shopped", but without the "I can tell by the pixels" rejoinder.

I mean sometimes they're right, but honestly in this day and age does that even matter?

Re: Google Cloud Fraud Defence is just WEI repackaged

#276
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

what alternative to WEI do you propose? it solves a bajillion Internet-existential problems. it is definitely a crisis. the bot problem is at least as serious as facebook, gmail serving without https. the fact that this kind of comment gets downvoted proves my point. so what if you personally don't like WEI? it doesn't mean the problems aren't real... that aside, i don't know how people say stuff like "malicious forc…

People use iMessage because it has worked for a long time, during which all the leading alternatives were terrible. Maybe they still are cause I'm still not convinced that RCS even works reliably, seeing how Android users go on WhatsApp instead.

Re: Google Cloud Fraud Defence is just WEI repackaged

#277

Earlier quoted context omitted.

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either Do you think this won’t also be bypassed, by bribing people to scan QR codes and spoofing location etc.?

The person who scanned to QR code is knowable. They have their IMEI encoded in the response.

Allegedly can be spoofed.

But regardless, I imagine scammers will circumvent this to buy products, login to bank accounts, etc. of the exact users they’re targeting. The user will be presented with “Scan this QR code for $100” as the scammer is logging into their account with spoofed metadata.

Re: Google Cloud Fraud Defence is just WEI repackaged

#278
Do we know if this is immediately going to slot in wherever reCAPTCHA is currently used / is there a rollout plan? Or will site operators manually opt into the new system? Is there even a way to opt out?

I can think of many sites where, for users that trigger captchas often, introducing a multi-device workflow is even worse for those users than clicking traffic light images. An automatic rollout would be hostile to those operators!

Re: Google Cloud Fraud Defence is just WEI repackaged

#279

Earlier quoted context omitted.

Turns out that identifying a problem doesn't help without a workable solution/alternative.

I hate this trite and the managers that say "don't bring me problems, bring me solutions" nonsense. I'm not the person to be able to fix it so the solution is make the problem known so others responsible can fix it. If I could fix it, I wouldn't be telling you about the problem. If anything, I would tell you how I fixed an issue in some stand up or other of the many meetings scheduled keeping me from working.

I am only aware of two solutions:

1) proof of identity, tying accounts to real-world things that are hard or impossible to replicate

2) proof of work, tying accounts or actions to the ability to run computations

Proof of identity in theory can solve the problem but at the cost of privacy.

Proof of work can be defeated but has the possibility of preserving privacy.

Re: Google Cloud Fraud Defence is just WEI repackaged

#280

Earlier quoted context omitted.

> Windows computers Ship with a chromium fork called Edge

Edge isn't Chrome though, is it? Like, its not shipped by Google, it doesn't bug you to log in with a Google account, doesn't ship metrics back to Google, right? Not quite the same thing now is it?

The usual complaint is that Chromium dominates as an engine. I don't fully understand the complaint because anyone can fork it, but maybe they're (rightfully) concerned nobody will fork it because Google controls the web standards, or they're concerned Chrome could stop using the open version of the engine.
Post reply on HN