Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

261–270 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#261

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#262
post #57

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)

Also in adjacent countries like Vietnam etc., where even ragtag street food vendors have a QR code sticker on their stall/cart.

It's so common that people pay without even talking or confirming; I've seen customers just take their phone out, point at the QR, and walk away, and the shopkeeper says nothing. I'm assuming the shopkeeper gets a notification on their phone and trusts regular customers,

but how easy would it be to secretly place your own bank account's QR code on top of a shop's QR? People who wait for a confirmation notification will catch it immediately, but by then the customer has already paid the attacker and the transaction can't be just reversed. Repeat it in several places, and a thief to snatch quite a few payments before the parasite stickers are all taken down.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#263

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

Looks similar but is a different thing entirely. That is for allowing a someone to take money from your account.

Because the concept of credit/debit cards is batshit insane that only serves to finance organized crime.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#264

Wow. So you will need a mobile device in future to browse the web, and Google will use mobile device identifier to de-anonymize you. And I assume they also carefully designed this to make life little harder for alternative search engines, their competitors. And probably they will not provide collected user data to competing advertising platforms to make them less competitive as well. Also the example is ridiculous, t…

I will stop using those websites altogether. You know, its funny, I don't think I've ever seen captcha on HN once.

You need one to sign up lately I believe. Which is really all it takes if your identity is required for the captcha and gets associated with your account forevermore.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#267

Earlier quoted context omitted.

I guess history made us different. Personally I have reasons to be equally distrustful to anyone who wants to know too much about me, but much more afraid of my gov't than overseas entities.

In this specific case, why fear the government? My government has already seen my government-issued ID. If my government hasn't worked out my phone number, they can always ask the phone company. My address is required for the ID, voting, and filing taxes. I don't see how the government learns anything from this? Conversely, I would like to believe most companies do not have my government-issued ID, nor a lot of the i…

From an American perspective, i don't trust the government with the implementation details, nor do I trust our political climate, misaligned incentives, and general disinterest in good governance to implement something so sensitive.

If I lived in say, Sweden, I feel much more comfortable trusting their government to implement. In America, I feel I must always vote in a way that prevents giving any power to the government that I wouldn't want my political opponents to have over me.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#268
post #196

Earlier quoted context omitted.

Simply live somewhere that doesn’t have a broken electoral system.

Like the Moon or Mars? The power is not something for the people for free.

Some Western European democracies have a well-functioning democracy. The people voting are still humans, a substantial portion votes for racist parties that economically only benefit big corporations and not them, but the damage is limited because there is no winner-takes-all. Everyone has to accept compromises.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#269
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

And you must be signed in.

I frequently get flagged as suspicious activity and have to pass a captcha when trying to use the Google verbatim search function on a signed out Firefox browser on android.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#270

Earlier quoted context omitted.

Smartphone is just a small computer. I don't see hiw what you say makes sense.

It's a small computer that I don't really control with a horrible UI, horrible privacy, and nothing but perverse incentives. ("download the app!")

You need LineageOS or GrapheneOS
Post reply on HN