Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

171–180 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#171

Earlier quoted context omitted.

I expected mostly snark from my earnest question, And got it. Ok, concrete scenario. What about homeless people using the computer at the library? Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm.

> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Sure they would. Cloudflare has already arbitrarily blocked entire swathes of the internet. Captcha as well. Your average user ends up going to the path of least resistance, and end up with a compliant ISP or carrier that's doing all sorts of censorship and gatekeeping and siloing and funneling.…

They just didn’t want a Temu Cory Doctorow answer.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#172

Earlier quoted context omitted.

> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Why wouldn't they? Google is notorious for making marginalized people's lives harder if it can make them money. Some examples: - Hosting Palantir's ImmigrationOS, used by ICE to track immigrants - Actively removing tools marginalized people use to protect themselves against ICE, such as ICE-track…

Illegal immigrants =/= marginalized people

[flagged]

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#173
post #141

Earlier quoted context omitted.

I will be unable to solve the phone verification because I use LineageOS for microG, but any fraudster can just buy a bunch of $30 android phones. Many people have trouble using a smartphone, so they use dumbphones, but they will be locked out. Many people just don't have any mobile phone because they don't think that it is useful.

Google is mostly interested in abuse that happens beyond the scale of how many $30 phones you can buy.

Google is interested in, like other tech companies, identifying users by tying them to their phones. Other ai defense companies are trying to get photos and IDs. This is just another take on the same subversive activity.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#174
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#175

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

Maybe ai companies should have invested any of those billions of dollars into safe and equitable ways of rolling out their new surveillance machines. Oh right that was never the point and this only serves to further that. Got it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#176

Wow. So you will need a mobile device in future to browse the web, and Google will use mobile device identifier to de-anonymize you. And I assume they also carefully designed this to make life little harder for alternative search engines, their competitors. And probably they will not provide collected user data to competing advertising platforms to make them less competitive as well. Also the example is ridiculous, t…

Well, internet is dead anyway so they can keep the keys to the kingdom. I frankly do not care anymore. The meek shall inherit the Earth

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#177

How are people stopping bots reliably?

The first step is to write down why you are stopping bots and which bots you are stopping. If an LLM is buying things from your web store, that's good. You are making money on that, and you shouldn't stop it.

The lifetime value of a LLM may be less than a real person. Especially if you consider things like word of mouth marketing.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#178

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

You're right, we need big tech to protect us from the problems big tech created. In the olden 20th century, we had a term for that...

You know that protection racket where the mobster came to my corner store and says if I don't pay him he will come later and rough me up? This is a worse deal than that.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#179
Prime "drink verification can" bullshit. If you don't have a Google Approved Phone, the solution is to go fuck yourself. But what else would you expect from modern day and age Google?

Traditional CAPTCHA was heading for the graveyard for a while now, because the overlap between the dumbest of users and the smartest of AIs is too severe. But aggressively doubling down on the user-hostile garbage isn't the solution.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#180

Earlier quoted context omitted.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

We might need to redo this whole Internet thing because this is insanity.
Post reply on HN