Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

181–190 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#182
post #99

I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…

Whats to stop malicious actors (bad extensions, compromised cdn, etc.) from painting over the qr code or injecting their own? This is so incredibly terrible.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#183
post #162

Earlier quoted context omitted.

They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying

QR payments in china was already prevasive before contactless payments became prevasive in the west. And as others say: not all phones supported nfc at the time. Remember iBeacons on iP5? Wechat and Alipay was already everywhere by then

Only because you typo'd twice: it's "pervasive".

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#184

Earlier quoted context omitted.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

In a free market, the content provider is free to put whatever guardrails they feel appropriate. Loginwall, Paywall, CaptchaWall.

If you don't like that provider, you are free to pick another.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#187

Earlier quoted context omitted.

Why the hell would they care who is buying it? They're getting paid either way. The only reason they'd care is because they want to sell your personal information.

That is an incredibly long bow to draw from someone that obviously doesn’t know what they’re talking about and is willing to make massive jumps to conclusions. Do you know how ecommerce works? I agree that it is a bit absurd, but not nearly as absurd as your claim of “the only reason”.

People on this site don't really think deeply about what they type. They just say whatever is the most cynical in order to farm up votes

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#188
post #56

Earlier quoted context omitted.

Where is this specified? I don't see that in TFA.

The example they give in TFA is having the user scan a QR code, presumably from a mobile device.

But that's not a specification

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#189
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

reminder that any company which has a legal obligation towards you (GDPR requests, refunds, filling a complaint etc) can be contacted directly and forced to do it manually if you cannot use their web interface due to being blocked by Cloudflare & other captchas

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#190
post #184

Earlier quoted context omitted.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

In a free market, the content provider is free to put whatever guardrails they feel appropriate. Loginwall, Paywall, CaptchaWall. If you don't like that provider, you are free to pick another.

1. Free markets do not exist

2. If free markets did exist they would not conform to the theory that people are using when they think of what free markets are, since people do behave rationally, power dynamics are real, and no consumer can have all of the information needed to make rational decisions even if that information were available

3. The market is providing solutions to its own failures without fixing the underlying failures because it is more profitable this way. Is buying something from a company that mitigates a problem created by the same company actually a free market, or is it just extraction?

Post reply on HN