Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

231–240 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#231

Earlier quoted context omitted.

> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm. Honestly, if you ask such terminally naive questions don't be surprised to get sarcasm in reply. Google does cut off access to chunks of people if it deems it profitable to do so!

It doesn't matter how "naive" you think a question is. Nobody here deserves sarcastic remarks in response to a good-faith question. Literally the first guideline under "In Comments" is: > Be kind. *Don't be snarky.* https://news.ycombinator.com/newsguidelines.html

Oh please. It wasn't even that snarky. It's also still a valid and correct (as far as anyone can tell) answer to the question.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#232

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

The alternative would be tar traps that only a bot would “see” and interact with and thus be caught by. Default to annoying machines not people.

Your idea works for generic crawlers.

That doesn't work for targeted bots. A major benfit of device attestation is to stop the hordes of custom bot creators who try all sorts of ways to make a buck off of your platform such as sms toll fraud, credit card testing, ad fraud, account takeovers, stolen card laundering, gift card laundering, botting for pay for platform / ecosystem benefits, paid harassment, the list just keeps going.

Some aps such as okta, banking, and others already check platform verfication. Websites can't currently until device attestation.

Personally, I hate the concept, but I also hate spending a large amount of time fighting mal-actors on my platform in a completely unbalanced fight. There are tons of them, and they have all the profit incentive. There's a few of us, we only take losses. They can lie all they want, we can't really trust any facts except kinda the credit card and the device attestation.

Like everything, it's a shitty compromise, but, as a platform runner, if I can leverage google's signal and cut 95% of my malicious botting users, guess what I'm going to do.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#233

reCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for…

The GitHub one I recently tripped on was the worst of all time. Part one of 9 or something, which of these three next sounds are bees? Or some small man rotating around spaces on a map. I have an eInk screen and it was nearly impossible to see. Extremely painful and ridiculous.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#235

Earlier quoted context omitted.

How though? Can you also avoid DDoS simply by designing your system to not care if the requester is a bot or not. Let's say I'm running https://grep.app/ for example. AI bots start heavily using it, costing me a ton of money. How would you magically design this so it doesn't matter if the end bots are using it?

Rate limit individual clients.

Let's play this out: how do you determine individual clients? By ip? By seasionid?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#236

Earlier quoted context omitted.

One of them pretends to hold elections.

Which public corporation do you think doesn't hold elections?

Google. The Class B stock setup means Class A shareholders are shouting into a void.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#237
The efforts by Googles, Meta, TikTok, X and AWS etc. to fight fraud and other financial crimes are probably largely deficient. They earn significant revenue from crime and criminal activity. Compared to banks which are required to prevent financial crimes up to personal criminal liability of employees there are no comparable rules for social media platforms.

How do two service businesses get treated so differently by law?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#238
post #54

Earlier quoted context omitted.

I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…

I guess history made us different. Personally I have reasons to be equally distrustful to anyone who wants to know too much about me, but much more afraid of my gov't than overseas entities.

In this specific case, why fear the government?

My government has already seen my government-issued ID. If my government hasn't worked out my phone number, they can always ask the phone company. My address is required for the ID, voting, and filing taxes. I don't see how the government learns anything from this?

Conversely, I would like to believe most companies do not have my government-issued ID, nor a lot of the information on it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#239

yeah im not doing that

You don’t need to. As long as the dumb majority goes along with it, your options are to capitulate or get locked out of society.

An increasing percentage of the dumb majority are opting for dumb phones and plenty of people still use laptops, it doesn't have to be anywhere remotely close to a majority for many analytics-obsessed site owners to see the drop in sales and opt for another solution.

In any case, sites using an extremely restrictive mode of recaptcha during ddos attacks will just be one segment of a very fragmented digital future, not society as such

Post reply on HN