Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

311–320 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#311

Earlier quoted context omitted.

I used to know some Americans who were on the poorer end of the spectrum, and apps that paid you for performing fitness activity and such weren't uncommon in that demographic. Not as much of a thing in Europe for some reason. I believe the cheap Chinese pirate TV boxes that are somewhat popular in the US these days are also in botnets, which is likely how the vendors make them so cheap.

What are these Chinese pirate devices? This sounds fascinating.

https://krebsonsecurity.com/2025/11/is-your-android-tv-strea...

Re: Google Cloud Fraud Defence is just WEI repackaged

#312

Earlier quoted context omitted.

I am only aware of two solutions: 1) proof of identity, tying accounts to real-world things that are hard or impossible to replicate 2) proof of work, tying accounts or actions to the ability to run computations Proof of identity in theory can solve the problem but at the cost of privacy. Proof of work can be defeated but has the possibility of preserving privacy.

>Proof of identity in theory can solve the problem but at the cost of privacy. All current implementations: yes. I do think there are some privacy preserving solutions, but they're obviously imperfect. But assuming you have a central authority that can validate and sign valid government identification, it seems like some sort of ZK scheme could allow one to verify that they have a valid government issued ID, but with…

From what I've seen no such solution guarantees privacy to the user if the signing body (or the government) and the website collude to deanonymize the user.

Re: Google Cloud Fraud Defence is just WEI repackaged

#314

Earlier quoted context omitted.

hacker news when discovering that apple deployed WEI, for ages, with beloved IT company Cloudflare, affecting hundreds of millions of users: "aww, you're sweet" hacker news when reading that google is doing the same thing for the rest of the userbase: "hello, human resources?"

Really. I think HN hates Cloudflare with (quite unjustified if you ask me) searing passion.

In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year.

https://en.wikipedia.org/wiki/Matthew_Prince#:~:text=In%2020...

They're literally a government surveillance program larping as a private company, many such cases.

Re: Google Cloud Fraud Defence is just WEI repackaged

#315
post #55

Earlier quoted context omitted.

iPhones have attestation too: https://developer.apple.com/documentation/devicecheck/establ... It'll just be more clunky because you have to install their app.

I believe the latest versions of iOS just work from the browser, you only need to install the app for older versions of the OS. I don't know what technology they're using, but when I scanned the QR code it launched (downloaded?) an iOS app of sorts with one tap, similar to the way Google tried Instant Apps a few years back. Didn't even need to double tap the power button like usual.

App Clips -- very underutilized but also very cool. https://developer.apple.com/documentation/appclip

Re: Google Cloud Fraud Defence is just WEI repackaged

#316

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

Oh it's better than that now, if you can afford the up-front costs. You can set up a phone farm with cheap Google-certified devices, and the control software manages the Google accounts and botnet connection (through multiple residential proxies, of course). All of these attestation games are DOA.

Re: Google Cloud Fraud Defence is just WEI repackaged

#317
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

> rapidly becoming Always has been. Google was creating cartels like the "Open Handset Alliance" literally decades ago. Via their control of Chrome and Search which are both monopolies, Google holds absolute authority on how websites are rendered and if websites can be found.

Huge fan of Kagi so far - especially SmallWeb if you do want to find websites that probably would not hit the top of Google search results

Re: Google Cloud Fraud Defence is just WEI repackaged

#318
post #89
post #77

Earlier quoted context omitted.

>Why? What's LLM generated? How can you tell? Not the guy you're responding to, but: 1. The high number of (em) dashes is suspect, though it's unclear whether they manually replaced the em dashes or is actually human generated. 2. "One additional failure worth noting: one incident response professional in the HN thread, raised a concern that operates independently of the bot problem" feels out of place for a content…

Looks like the moderators are actively deleting comments that call out AI generated articles now. Grim. This comment will probably be deleted too.

What did you see that made you think that? (It's entirely untrue btw.)

We haven't said anything specific about genai articles but if you've seen https://news.ycombinator.com/newsguidelines.html#generated or https://news.ycombinator.com/item?id=47340079 it shouldn't be hard to extrapolate.

Re: Google Cloud Fraud Defence is just WEI repackaged

#319

What Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human. 1. lots of laptops have fingerprint readers & TPM2 build-in 2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly. Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and…

neither 1 nor 2 can prove you're a human. sorry

neither can Google Cloud Fraud Defence, and yet we're here

Re: Google Cloud Fraud Defence is just WEI repackaged

#320
post #49

Related: Google Cloud fraud defense, the next evolution of reCAPTCHA https://news.ycombinator.com/item?id=48039362

Wrong link. https://news.ycombinator.com/item?id=48039362

Thanks! I've s/48061938/48039362/'d the GP.
Post reply on HN