Earlier quoted context omitted.
> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm. Honestly, if you ask such terminally naive questions don't be surprised to get sarcasm in reply. Google does cut off access to chunks of people if it deems it profitable to do so!
It doesn't matter how "naive" you think a question is. Nobody here deserves sarcastic remarks in response to a good-faith question. Literally the first guideline under "In Comments" is: > Be kind. *Don't be snarky.* https://news.ycombinator.com/newsguidelines.html
Google Cloud fraud defense, the next evolution of reCAPTCHA
231–240 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#232Earlier quoted context omitted.
But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.
The alternative would be tar traps that only a bot would “see” and interact with and thus be caught by. Default to annoying machines not people.
That doesn't work for targeted bots. A major benfit of device attestation is to stop the hordes of custom bot creators who try all sorts of ways to make a buck off of your platform such as sms toll fraud, credit card testing, ad fraud, account takeovers, stolen card laundering, gift card laundering, botting for pay for platform / ecosystem benefits, paid harassment, the list just keeps going.
Some aps such as okta, banking, and others already check platform verfication. Websites can't currently until device attestation.
Personally, I hate the concept, but I also hate spending a large amount of time fighting mal-actors on my platform in a completely unbalanced fight. There are tons of them, and they have all the profit incentive. There's a few of us, we only take losses. They can lie all they want, we can't really trust any facts except kinda the credit card and the device attestation.
Like everything, it's a shitty compromise, but, as a platform runner, if I can leverage google's signal and cut 95% of my malicious botting users, guess what I'm going to do.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#233reCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for…
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#234with cloudflare, I cannot use my old browser, I cannot browse many sites without javascript or cookies.
recaptcha? that prevents me from doing business with many sites, let alone browse.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#235Earlier quoted context omitted.
How though? Can you also avoid DDoS simply by designing your system to not care if the requester is a bot or not. Let's say I'm running https://grep.app/ for example. AI bots start heavily using it, costing me a ton of money. How would you magically design this so it doesn't matter if the end bots are using it?
Rate limit individual clients.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#236Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#237How do two service businesses get treated so differently by law?
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#238Earlier quoted context omitted.
I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…
I guess history made us different. Personally I have reasons to be equally distrustful to anyone who wants to know too much about me, but much more afraid of my gov't than overseas entities.
My government has already seen my government-issued ID. If my government hasn't worked out my phone number, they can always ask the phone company. My address is required for the ID, voting, and filing taxes. I don't see how the government learns anything from this?
Conversely, I would like to believe most companies do not have my government-issued ID, nor a lot of the information on it.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#239yeah im not doing that
You don’t need to. As long as the dumb majority goes along with it, your options are to capitulate or get locked out of society.
In any case, sites using an extremely restrictive mode of recaptcha during ddos attacks will just be one segment of a very fragmented digital future, not society as such