Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

211–220 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#212
I don't really get how this stops captcha solving as a service, which is the actual way that scaled recaptcha solving is done? Those things are incredibly cheap and are staffed by humans anyway. Instead of selecting grainy busses, they will just scan the image with their phones.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#213
post #3

The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.

I think the pathetic thing about this is that it’s so much less intuitive than stuff like cloudflare and Anubis.

Google, a multi-billion dollar company, is going to make the customers of their corporate clients pull out a phone and do some bullshit just to visit a website.

Meanwhile, when Cloudflare/Anubis verifies you there’s zero required interaction and you barely even see the anime character because it all loads so fast. At most Cloudflare makes you check a box.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#214
post #131

Earlier quoted context omitted.

They don't like contactless technology or what? I don't think that scanning a QR code is significantly more involved but it's enough to be annoying

I think partly because Google and Apple controlled the contactless bits of the phones for many years, the non-OS-makers like WeChat and AliPay made use of the open technology of QR codes. I think theoretically you could build equivalent things as they have with NFC today on those platforms but on the other hand being able to set up a “POS” with nothing more than a printer does have an appeal to it, even if writable n…

I think there is also something about how easy it is for a business to adopt a QR code by just needing to print one out instead of having to go out and buy a whole payment terminal.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#215
post #128
post #99

I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…

But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#216
the mobile phone requirement would mean I end up avoiding sites that use that method. I'm not sure how many friends and family can be convinced, but I can try . (most people tend to give up any and all security measures if it means getting to see the fluffy kitten though, so my hopes aren't very high)

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#217
I think it’s becoming hard to ignore that the Internet has fundamental flaws from a game theoretical view. I hope that we can skip the step of having Google as the feudal lord who saves us from anarchy though.

How about we start with some accountability for entities that host fraud? The main reason we can have relative anonymity in public is part trust and partially because you can get physically taken out if you cross the line. I understand there are some real limitations with enforcing accountability on the Internet, but perhaps that’s where we should be focusing.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#218
post #163

Earlier quoted context omitted.

What if neither side represents your interests? What "election" is there in that case?

Can you candidate yourself in that election?

I'm sure many are tempted to dismiss this comment, but I think it's actually great. It's incredibly easy to complain about the options out there, really easy to vilify any or all of the parties as controlled by satan/evil corporations/communists/fascists.

What's harder?

Convincing enough people to matter (in some kind of election-based system) to get behind your platform - either with you as a candidate, or working to promote a candidate or party or movement that you do believe in.

People talk like their changemaking ideas are very widely held - the way people talk it's like they believe 75%+ of the country must actually agree with them - but then they don't run for office on such a popular platform that it should be a sure election win, yes even with countervailing forces such as electoral college, Senate, etc.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#219
post #57

Earlier quoted context omitted.

You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)

Thankfully I don't live in China. Unfortunately the totalitarian government is a larger concern than the QR codes.

Which one?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#220

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

One alternative is to make simple, efficient, and where appropriate even static sites that can scale to meet the demand.

The HIBP hashes distribution is a great example.

Post reply on HN