Earlier quoted context omitted.
> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.
I'm pretty sure it's one of the revenue models for those free tv/movie boxes. You can even see them at best buy. Absurd.
Google Cloud Fraud Defence is just WEI repackaged
291–300 of 394 posts
Re: Google Cloud Fraud Defence is just WEI repackaged
#292Earlier quoted context omitted.
> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.
I used to know some Americans who were on the poorer end of the spectrum, and apps that paid you for performing fitness activity and such weren't uncommon in that demographic. Not as much of a thing in Europe for some reason. I believe the cheap Chinese pirate TV boxes that are somewhat popular in the US these days are also in botnets, which is likely how the vendors make them so cheap.
Re: Google Cloud Fraud Defence is just WEI repackaged
#293I do wonder how people who work on this don't see themselves as the bad guy.
Re: Google Cloud Fraud Defence is just WEI repackaged
#294Earlier quoted context omitted.
I hate this trite and the managers that say "don't bring me problems, bring me solutions" nonsense. I'm not the person to be able to fix it so the solution is make the problem known so others responsible can fix it. If I could fix it, I wouldn't be telling you about the problem. If anything, I would tell you how I fixed an issue in some stand up or other of the many meetings scheduled keeping me from working.
I am only aware of two solutions: 1) proof of identity, tying accounts to real-world things that are hard or impossible to replicate 2) proof of work, tying accounts or actions to the ability to run computations Proof of identity in theory can solve the problem but at the cost of privacy. Proof of work can be defeated but has the possibility of preserving privacy.
All current implementations: yes. I do think there are some privacy preserving solutions, but they're obviously imperfect. But assuming you have a central authority that can validate and sign valid government identification, it seems like some sort of ZK scheme could allow one to verify that they have a valid government issued ID, but without disclosing which one it is.
I still don't love the idea, but it sure seems better than everything else I've seen proposed.
Re: Google Cloud Fraud Defence is just WEI repackaged
#295Earlier quoted context omitted.
> Ok, so enlighten me which standard of monopoly they're so obviously breaking? Breaking? They're being a monopoly by having a huge market share. A majority of browers are directly branded chrome, and the chrome team has strong codebase control over most of the alternatives too. Especially on desktop. It's that simple. > I'm not arguing it requires 100% marketshare. I'm just pointing out there are tons of workable co…
> having a huge market share. Marketshare alone isn't a defining part of if a product is a monopoly. > majority of browers are directly branded chrome They're not Chrome, in many extremely important aspects. > The choices of users don't change whether something is a monopoly The fact users can make a choice is a huge part of the argument that Chrome isn't a monopoly. There are lots of competitors out there that can b…
Yes it is. You're thinking of something else.
> The fact users can make a choice is a huge part of the argument that Chrome isn't a monopoly.
That argument is wrong.
It's size and market power. If users could change but don't, the monopoly company still has huge power.
> Lay's sells like 60% or so of the chips sold in the US. Are they a monopoly?
They're at least close, yeah.
Re: Google Cloud Fraud Defence is just WEI repackaged
#296Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?
Re: Google Cloud Fraud Defence is just WEI repackaged
#297Earlier quoted context omitted.
The person who scanned to QR code is knowable. They have their IMEI encoded in the response.
Allegedly can be spoofed. But regardless, I imagine scammers will circumvent this to buy products, login to bank accounts, etc. of the exact users they’re targeting. The user will be presented with “Scan this QR code for $100” as the scammer is logging into their account with spoofed metadata.
Not on a non-rooted device, which won't pass attestation.
Re: Google Cloud Fraud Defence is just WEI repackaged
#298Earlier quoted context omitted.
Why do you continue to extend the benefit of the doubt to your former employer when they have shown themselves to be untrustworthy again and again?
For one, I got to see how utterly insane and off-base many of the conspiracy theories around Chrome were compared to reality.
Re: Google Cloud Fraud Defence is just WEI repackaged
#299Earlier quoted context omitted.
hacker news when discovering that apple deployed WEI, for ages, with beloved IT company Cloudflare, affecting hundreds of millions of users: "aww, you're sweet" hacker news when reading that google is doing the same thing for the rest of the userbase: "hello, human resources?"
I thought that cloudflare system worked on any hardware and the tokens are anonymous. Did that change at some point? If it didn't change, then yeah it should get a very different reaction! (Edit: it looks like the new system is still private and still interlinked with the old system that lets you use any hardware? I think?) Also I don't know how you could have missed the widespread criticism of apple and especially c…
I think it has also blessed Amazon's WAF
Cloudflare has a turnstile product that i'm sure uses this apple IDS token
Mobile Safari generally is not shown Cloudflare captchas or similar because of Apple-Cloudflare cooperation. it's not complicated.
Apple calls it a "Personal Access Token" but that makes it sound more like a DRM scheme - which it sort of is, it is managing your right to a free-as-in-beer access scheme - than a broad web integrity environment solution
Re: Google Cloud Fraud Defence is just WEI repackaged
#300Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?