Google Cloud fraud defense, the next evolution of reCAPTCHA
211–220 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#212Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#213The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.
Google, a multi-billion dollar company, is going to make the customers of their corporate clients pull out a phone and do some bullshit just to visit a website.
Meanwhile, when Cloudflare/Anubis verifies you there’s zero required interaction and you barely even see the anime character because it all loads so fast. At most Cloudflare makes you check a box.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#214Earlier quoted context omitted.
They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying
I think partly because Google and Apple controlled the contactless bits of the phones for many years, the non-OS-makers like WeChat and AliPay made use of the open technology of QR codes. I think theoretically you could build equivalent things as they have with NFC today on those platforms but on the other hand being able to set up a “POS” with nothing more than a printer does have an appeal to it, even if writable n…
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#215I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…
But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#216Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#217How about we start with some accountability for entities that host fraud? The main reason we can have relative anonymity in public is part trust and partially because you can get physically taken out if you cross the line. I understand there are some real limitations with enforcing accountability on the Internet, but perhaps that’s where we should be focusing.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#218Earlier quoted context omitted.
What if neither side represents your interests? What "election" is there in that case?
Can you candidate yourself in that election?
What's harder?
Convincing enough people to matter (in some kind of election-based system) to get behind your platform - either with you as a candidate, or working to promote a candidate or party or movement that you do believe in.
People talk like their changemaking ideas are very widely held - the way people talk it's like they believe 75%+ of the country must actually agree with them - but then they don't run for office on such a popular platform that it should be a sure election win, yes even with countervailing forces such as electoral college, Senate, etc.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#219Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#220Earlier quoted context omitted.
I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…
But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.
The HIBP hashes distribution is a great example.