Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

241–250 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#241
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

No surprises here, though of course disappointment when it comes to fruition.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#242
post #128

Earlier quoted context omitted.

But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

No, we don't, or shouldn't ask people to check the URL itself, because of homonym attacks are a thing. Goal is to make sure that your credentials can't be compromised by surfing the wrong website (e.g. by using Passkeys instead of passwords).

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#243
post #141

Earlier quoted context omitted.

I will be unable to solve the phone verification because I use LineageOS for microG, but any fraudster can just buy a bunch of $30 android phones. Many people have trouble using a smartphone, so they use dumbphones, but they will be locked out. Many people just don't have any mobile phone because they don't think that it is useful.

Google is mostly interested in abuse that happens beyond the scale of how many $30 phones you can buy.

They're mostly interested in having a complete record of all users' internet activity tied uniquely to their identity.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#245
Like many, I've already trained myself to commit to giving up immediately after the second bus or traffic light or puzzle (some of which I don't even understand anymore). Sounds like my life will not be all that different.

Worst case scenario, if this neuters my sovereign and all powerful linux desktop from some critical business I can't avoid (which remains to be seen), it sounds like I will have to have some scripts and a dummy android phone in my home lab as a sort of second router.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#246

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

One alternative is to make simple, efficient, and where appropriate even static sites that can scale to meet the demand. The HIBP hashes distribution is a great example.

“Demand” has very little to do with any of the problems bots cause on the internet today.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#247

Earlier quoted context omitted.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

> press win+R ctrl+V LOL is this real? I guess yes, because yesterday ReCaptcha asked me to screenshot a QR-code with the mobilephone :-D

People are constantly made to jump through strange hoops to do things on the internet. Unless you're really keyed in to what's going on, it's easy to fall for stuff like that.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#248
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…

> I expect that it will initially not use it

it's boiling the frog method. Moving too fast means backlash, but a slow, step by step transition where each step seems reasonable, but ultimately end up with a locked down device, is how they aim to achieve it. And people would be too lazy to complain until the last few steps, by which time it would be too late.

Post reply on HN