Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

221–230 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#221
post #45

What funny timing: After being hounded with CAPTCHAs every time I tried to search from the URL bar for the past week, not two hours ago I switched everything over to DDG. Great work, Google!

I thought it's just happening to me. I tried to watch my computer's network activity to see if anyone has hijacked my IP. I closed Gmail and YouTube tabs because I find that they are the ones which pings to the outside world a lot more than other tabs I have opened. I even restarted my modem two times. Didn't work.

So I decided to...use Firefox a lot more with DDG (I use FF for mostly privacy-sensitive stuff like checking my financial accounts, but now I use it for a lot more browsing stuff).

Seems like it is the Chrome browser over-reacting.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#223
post #164

Earlier quoted context omitted.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

In passkeys the bluetooth is used for the actual authentication protocol...

Sometimes, sort of. Most passkey usage doesn’t involve bluetooth. When it does, there’s no real data being sent over bluetooth, just a meaningless hash that can be confirmed using a secret inside the QR code.

So really, it’s like I said, Bluetooth is used to make sure that the device consuming the QR code is actually near the device that’s displaying the QR code.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#224

Earlier quoted context omitted.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

Yes. The technical name for this FIDO2 QR code flow is caBLE (Cloud Assisted Bluetooth Low Energy).

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#225
post #57

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)

Adding friends, shopping, logging in on PC, binding accounts for after-the-fact SSO, etc..

This is all done with QR codes here.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#226

I’m trying to use my phone less and less. Ideally I’d like to even switch a dumb phone. But tactics like this will make that nearly impossible if every website starts requiring a QR code scan on a authorized smartphone.

Tactics like this will make me get a dumb phone and stop using those websites. If that means no more credit cards, online shopping, etc so be it. You have to draw the line somewhere.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#227
post #54

Earlier quoted context omitted.

This is going to make my grapheneos journey a bit more exciting. How wild to force users through an official google identification for web browsing. Does the iPhone recaptcha app force you to login with a Google account? Seems we didn't need ID verification for the web to lose all anonymity.

I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…

one of these also rounds up people and sends them of to overseas concentration camps without due process. I think maybe white people still don't get what the rest of the world is living or experiencing.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#228

reCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for…

I think you're spot on. This will block and inconvenience legitimate users while fraudsters have no problem buying more phones.

Not a useful direction for real end users.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#229
post #201
post #99

I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` insta…

2020s will be remembered as the decade when companies stopped behaving in a trustworthy way, and normalized scanning random QR codes, downloading random apps, uploading photos of your face or documents, all as strange convoluted "verification" procedures. Scammers will love this

Companies were doing this all along. The 2020s will be remembered as the decade when we realized, too late, that the world began ending in the 2010s.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#230
post #96

The QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.

Scan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit I must not be the first one to think of this, right? Right???

Does it hurt Google if that happens? No, not really, unless it happens a lot and one of the victims happens to be a US senator or something. The value of the control this gives them, if adopted widely, is immeasurable, not to mention the ad-targeting value of identifying more people across devices.
Post reply on HN