Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

131–140 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#131
post #57

Earlier quoted context omitted.

You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)

They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying

I think partly because Google and Apple controlled the contactless bits of the phones for many years, the non-OS-makers like WeChat and AliPay made use of the open technology of QR codes. I think theoretically you could build equivalent things as they have with NFC today on those platforms but on the other hand being able to set up a “POS” with nothing more than a printer does have an appeal to it, even if writable nfc stickers cost 5 cents you still have to go buy some.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#132

Earlier quoted context omitted.

That means you're a peasant, and don't matter. Don't worry, they'll work with telecoms and carriers to ensure devices matching your budget are subsidized and made available at every possible opportunity.

I expected mostly snark from my earnest question, And got it. Ok, concrete scenario. What about homeless people using the computer at the library? Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm.

> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they?

Why wouldn't they? Google is notorious for making marginalized people's lives harder if it can make them money. Some examples:

- Hosting Palantir's ImmigrationOS, used by ICE to track immigrants

- Actively removing tools marginalized people use to protect themselves against ICE, such as ICE-tracking apps on the play store

- Intentionally aided Israel in committing genocide as part of Project Nimbus

- LGBTQ creator censorship on YouTube

Cutting off a small group of people they've repeatedly shown not to care about in the first place is a small price to pay to further cement their position as gatekeeper of the internet.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#134
We are much MUCH closer to "drink verification can" than to the time that greentext was written. Like many things in 2026, it's beyond fucking wild, it's a parody of itself.

And I don't see it getting better without government regulation. But states are now weaker than corporations. How can we expect them to take charge?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#135
> we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop using the new QR code-based challenge.

I'm so pissed off in advance. I hope that Google die and collapse in sudden bankruptcy before we have to support this crappy challenges that are totally user hostile!

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#136

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

You're right, we need big tech to protect us from the problems big tech created.

In the olden 20th century, we had a term for that...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#138
post #96

The QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.

Scan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit I must not be the first one to think of this, right? Right???

Hey at least in September they're going to stop you from installing F-Droid. For your safety, citizen!

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#139
post #122

Earlier quoted context omitted.

One of them pretends to hold elections.

Does it only count as an election if one’s favorite side wins?

What if neither side represents your interests? What "election" is there in that case?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#140

Earlier quoted context omitted.

> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…

>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.

They said "capable of Play Integrity attestation". It's a weasel statement. If you have GMS, you're capable of performing PIA attestation, you just might fail. So it's strictly true, but doesn't tell us anything about whether it requires PIA.
Post reply on HN