Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

231–240 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#232

Earlier quoted context omitted.

Turns out RMS has always been right. How surprising.

Turns out that identifying a problem doesn't help without a workable solution/alternative.

nonsense on all levels.

RMS has offered broadly solutions/alternatives since the beginning, along with reporting early on trends that other people ignore.

Re: Google Cloud Fraud Defence is just WEI repackaged

#233

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

I'm afraid it's far less enticing. The usual offer is "To continue playing, pay $0.99 or hit AGREE to share your internet connection with Legit Services Inc."

And that's assuming they're nice enough to ask at all.

Re: Google Cloud Fraud Defence is just WEI repackaged

#234

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

https://www.fbi.gov/investigate/cyber/alerts/2026/evading-re...

> The following methods can be used to acquire residential IP addresses for a residential proxy network:

> Software development kit (SDK) partnerships: Proxy services convince mobile application developers to include their SDK in applications in exchange for payment for each person who downloads the application. Individuals download the application and accept the terms and conditions, allowing the SDKs to run in the background and route proxy traffic through users' devices.

> Virtual private network (VPNs) with hidden terms of service: Free VPN services may enroll users' devices in a residential proxy network, without obtaining their consent. The details are often hidden in the terms of service, which most users do not read prior to download, or the language is difficult for the user to understand.

> [malware and compromised IoT devices]

> Passive income schemes: Proxy services convince people to download applications on their device that promise to pay them for their internet bandwidth. People often do not realize that criminals use their internet connection to commit cyber attacks

One reddit post says bandwidth sharing passive income schemes paid them $1 to $9 per month.

Re: Google Cloud Fraud Defence is just WEI repackaged

#235
I think I understand why Google wants to do this, and I think I understand why people are opposed to this particular solution.

It’s also worth noting that the author of this article is selling a proof of work solution to the problem.

I am fairly skeptical that proof of work is the right way to go here. A lot of users of the web are using older hardware. Adding a computational toll booth doesn't solve the problem in a world where people have differing amounts of compute to spend.

On the other hand, a botnet might have access to thousands of computers and may not actually care about waiting an extra 10 seconds. Or worse, they will come up with a custom solution on an ASIC that solves your proof of work puzzle thousands of times faster than grandma‘s laptop.

Re: Google Cloud Fraud Defence is just WEI repackaged

#236
I posted a comment on the announcement when it was posted here:

>As someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I have ever seen. A lot of companies have issues with ClickFix [1] and other social engineering campaigns and now Google wants to teach users that they should scan QR codes to proceed on a website.

>How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing QR code - you (realistically) can't. I wish we could - but those people don't work in tech, they will never know and I can't really blame them because at the end of the day they are just happy that they don't have to deal with tech after work.

>We have spent years of behavioural conditioning to prevent QR-code based phishing attacks (some people call it Quishing but I hate that term) and since the QR code is being scanned from a mobile device (99.99% of the time the private device), we have no EDR visibility on those devices and can't track what's happening if people scan it.

>This is more of an invitation for threat actors than it is something that holds them back.

[1] https://www.kaspersky.com/blog/what-is-clickfix/53348/

Re: Google Cloud Fraud Defence is just WEI repackaged

#237

Earlier quoted context omitted.

Do most people call Microsoft Edge or Safari "Chrome"? Are the security and privacy implications the same for Edge, Safari, and Chrome? Seems to me like they're still quite different products despite having some similar codebases!

Safari isn't based on Chromium.

Ah, you're right, still WebKit based.

Re: Google Cloud Fraud Defence is just WEI repackaged

#238
post #232

Earlier quoted context omitted.

Turns out that identifying a problem doesn't help without a workable solution/alternative.

nonsense on all levels. RMS has offered broadly solutions/alternatives since the beginning, along with reporting early on trends that other people ignore.

What is his solution to combatting botnets at scale?

Re: Google Cloud Fraud Defence is just WEI repackaged

#239
This seems to be an advertisement for Private Captcha. I don't know a lot about the service, but it seems inherently ablest. Does proof of work, support blind users? Does it is support special needs users with cognitive impairments? The QR code and photo support a wide variety of users. What not support a variety of methods. Why does it need to be one or the other?

Re: Google Cloud Fraud Defence is just WEI repackaged

#240
post #24

Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet

Turns out RMS has always been right. How surprising.

Root mean square?
Post reply on HN