Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

251–260 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#251

Captcha suggestion: force users to write something offensive/vulgar (we have a few "banned words"). Or to take a stance in Israel/Palestine. Whatever the response is, it'll unlikely be from an LLM.

But to use vulgar words an age attestation must be passed first! /s

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#252

Earlier quoted context omitted.

You're right, we need big tech to protect us from the problems big tech created. In the olden 20th century, we had a term for that...

You know that protection racket where the mobster came to my corner store and says if I don't pay him he will come later and rough me up? This is a worse deal than that.

Better turn on that 'free' Cloudflare 'bot' protection. Would be a shame if our, ahem, I mean, those botnets ddos'ed your site.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#253
post #124

Earlier quoted context omitted.

Discord has a feature where you can log into your account on your PC by scanning a code on your phone. So does Binance.

Those are good things though? They’re about logging in, on purpose. Not about attesting to Google that you have a proper smartphone as a proxy for your humanity, like this thing.

To prove you're not a bot, scan this QR code with Discord.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#254
post #184

Earlier quoted context omitted.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

In a free market, the content provider is free to put whatever guardrails they feel appropriate. Loginwall, Paywall, CaptchaWall. If you don't like that provider, you are free to pick another.

I'm not 'free' to pick another government site. There is only one.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#255

Earlier quoted context omitted.

Discord has a feature where you can log into your account on your PC by scanning a code on your phone. So does Binance.

But none of those options are requirements to access the service.

They're requirements to access my website though! To prove you're not a bot, scan this QR code - with Discord.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#256
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

Do you have an alternate solution? When we hear so many stories from HN'ers of their websites being hammered by out-of-control crawling and fetching and new levels of AI slop spam? This is something site owners choose to implement or not. They're the ones paying the extra hosting fees to handle potentially unwanted traffic, and dealing with spam that traditional CAPTCHA's are no longer effective against. Google's not…

Investigate the anti-bot sellers.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#258

Captcha suggestion: force users to write something offensive/vulgar (we have a few "banned words"). Or to take a stance in Israel/Palestine. Whatever the response is, it'll unlikely be from an LLM.

This is such a flawed view of LLMs. Sure it may block out frontier models but every local abliterated (and some non) will just say whatever you want.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#259
As someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I have ever seen.

A lot of companies have issues with ClickFix [1] and other social engineering campaigns and now Google wants to teach users that they should scan QR codes to proceed on a website.

How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing QR code - you (realistically) can't. I wish we could - but those people don't work in tech, they will never know and I can't really blame them because at the end of the day they are just happy that they don't have to deal with tech after work.

We have spent years of behavioural conditioning to prevent QR-code based phishing attacks (some people call it Quishing but I hate that term) and since the QR code is being scanned from a mobile device (99.99% of the time the private device), we have no EDR visibility on those devices and can't track what's happening if people scan it.

This is more of an invitation for threat actors than it is something that holds them back.

[1] https://www.kaspersky.com/blog/what-is-clickfix/53348/

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#260
post #128

Earlier quoted context omitted.

But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

Whoever told you that is the same person that advocated complex password rules with montly resets and no repeats.
Post reply on HN