Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

321–330 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#321

Earlier quoted context omitted.

> A properly designed government app Oof, that's not a great premise to take as a requirement right out of the gate. More counterexamples than examples for that one. > that uses cryptography to generate a deniable token that can't be cross-correlated but proves your humanity/age If it's actually deniable/anonymous then how would it work for rate limiting? If you can't correlate their activity then you don't know if t…

A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today.

> A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today.

So then you don't need either attestation or government IDs, right?

> The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today.

But how is that even useful? Is it good to exclude real people from Korea or South America? Do we really expect criminal organizations or for that matter even children to be unable to find a single adult EU citizen willing to anonymously loan them an ID?

It's about as plausible as criminals being unable to run their code on a device that can pass attestation. They're both authoritarians with a conflict of interest trying to foist a hellscape on everyone under a pretext their proposal can't even really address.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#322

Earlier quoted context omitted.

> My government has already seen my government-issued ID. If you have a government ID and all you use it for is voting and paying taxes, then they know that you vote and you pay taxes. If you have to use it for accessing the internet then they know everything you do on the internet. What you read, who you talk to, what you post, when you sleep, where you are at any given time -- it's very much not the same thing as j…

No they do not. A properly designed government app that uses cryptography to generate a deniable token that can't be cross-correlated but proves your humanity/age to a consuming site is manifestly different than Google adtech hoovering up as much of your activity as possible.

They could do it like that, but they won't do it like that, because tracking the population is a feature not a bug

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#324

Earlier quoted context omitted.

I live in France and no such payement system ever took off. We just pay with a standard credit card.

Standard card payment that you need to autorize on your phone in your bank's app...

That's 2FA though, not a QR code payment.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#325

Earlier quoted context omitted.

Kinda off topic question to google - when I do this labour of tagging your data so you let me use the internet - should I click on every box that has parts of the bus? Even if it's like one pixel? Follow up question - why ask people to work when you can just say "pay 1 shmeckel to view this content" and then use this money to pay for data taggers? Thank you for letting me use your internet!

Recaptcha contains a whole maximally obfuscated virtual machine with its own bytecode language. It measures your mouse movement, clicks, timing, cadence, hesitation, consistency, tile clicking order, etc. Ambiguous tiles are deliberately placed because the behavior they elicit from humans can be used to discern them from bots.

Yes, the "correct" reaction to the ambiguous tiles is to hover a bit indecisively. You need to waste a certain minimum amount of time on the CAPTCHA. I've found that applying videogame reflexes and zapping all the tiles in a short period of time is a fail, even if they're the correct tiles.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#326
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

"As part of our mission to enable a safe agentic web" drew an immediate swear from me.

What's happened here is yet another massive negative externality from AI. Because AI is such a fraud enabler, Google are now using that as an opportunity to end the open internet and competition in operating systems.

I'd much rather go the other way and make the AI wear identification. Crack down on both corporate and unlicensed AIs.

Edit: and of course it's also advertising killing the web, because the fraud in question is ad fraud. Need to force it into human eyeballs, not bots.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#328

Earlier quoted context omitted.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

I’m European, never encountered the system you describe. What is it and why does it exist? Apple Pay has been widely available since 2016. Why would anyone want to use some clunky QR-code thing instead?

For better or worse there's no such thing as "Europe" despite the wish of many on HN.

Such a system exists in, for example, Switzerland. Actually there are two such systems that aren't compatible. There are QR code invoices for domestic payments, where the code includes the target bank account details, amount to pay, transaction details etc. That's scanned by your bank app, direct p2p payment. And there is Twint, which is a domestic consumer payments app. The QR codes often contain short one time use codes that are looked up server side.

Why do people use them: because it's easy and the fees are low. Banks give you QR code invoices even for small businesses for free. Twint is a bit like Venmo, you can send to numbers in your address book for free, and for businesses they can do website integrations easily and even print out static QR codes to stick on market stalls etc.

Twint isn't as fast, convenient or reliable as NFC card payments so the card/tech companies still have an advantage. But it's been getting better. Maybe at some point the NFC elements in the card tech will become flexible enough to allow arbitrary mobile apps to be as good as tap-to-pay.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#329

Earlier quoted context omitted.

A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today.

> A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. So then you don't need either attestation or government IDs, right? > The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today. Bu…

> It's about as plausible as criminals being unable to run their code on a device that can pass attestation. They're both authoritarians with a conflict of interest trying to foist a hellscape on everyone under a pretext their proposal can't even really address.

How is the system proposed by GP authoritarian? It's not actually giving away any real PII. We could just argue that it would make Internet less usable for "illegal" immigrants who don't have a Gov ID - whcih can be seen as a problem already in itself, but still doesn't make that solution "authoritarian".

Post reply on HN