Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

331–340 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#331

Earlier quoted context omitted.

That means you're a peasant, and don't matter. Don't worry, they'll work with telecoms and carriers to ensure devices matching your budget are subsidized and made available at every possible opportunity.

I expected mostly snark from my earnest question, And got it. Ok, concrete scenario. What about homeless people using the computer at the library? Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm.

Google would throw homeless people in a furnace to generate electricity for their datacentres if they could. No, this is not sarcasm, I fully expect they would if they could.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#332
post #269

Earlier quoted context omitted.

And you must be signed in. I frequently get flagged as suspicious activity and have to pass a captcha when trying to use the Google verbatim search function on a signed out Firefox browser on android.

> And you must be signed in. I don't see any mention of that? Google Play services work fine without an account (although if you're the kind of person who doesn't sign in to a Google account on their Android phone, you're probably running a custom ROM or something)

Until now, I have never run "a custom ROM or something", but just the Android that came from the phone vendors and its updates.

Nevertheless, I do not have a Google account and I do not intend to have such an account.

Of course, this means that I cannot install any app from the official Google store, even if it is a free app. The requirement to login into your Google account should have existed only for payments, not for downloading a free app, but nonetheless Google does not work this way.

I already had problems with a bank that has terminated its Web-based online service, replacing it with an app that they refuse to provide for downloading, so that I could install it without having to open a Google account. Therefore I have also terminated my accounts with that bank.

I hope that this behavior will not spread to all remaining banks that still have Web-based online access.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#333

Earlier quoted context omitted.

A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today.

> A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. So then you don't need either attestation or government IDs, right? > The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today. Bu…

You're moving the goalposts. I was responding to your claim that any verification system involves the government getting a complete record of all online activity.

If you're willing to admit this is entirely possible from a technical standpoint, there's a separate question about how useful/valuable it is.

Making it harder for children to access extreme pornographic or violent content seems useful to me. Many advertisers want to be able to say they've shown ads to a human not a bot. Humans in WEIRD* countries have more valuable eyeballs than humans in the developing world.

If you don't solve for those use-cases in a privacy preserving way, adtech will do it in an intrusive way - which is what Google are doing in the OP.

*"Western, Educated, Industrialized, Rich, and Democratic"

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#334

Earlier quoted context omitted.

Which would be meaningful if phones weren't remotely controllable. So the net effect is every AI agent will also have and connect to a physical phone.

The attestation will include a unique ID of the phone, so that if you get banned you have to keep buying new phones and keep paying money to Google. Google won't stop this because it makes them money. And the official Google OS just won't feature remote-control software.

Or keep stealing IMEI IDs. Now regular people will start getting banned from the internet because of bot activity. You would open your phone one day and see "You have been disconnected from society" and there will be nothing you can do.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#335

Earlier quoted context omitted.

I guess history made us different. Personally I have reasons to be equally distrustful to anyone who wants to know too much about me, but much more afraid of my gov't than overseas entities.

In this specific case, why fear the government? My government has already seen my government-issued ID. If my government hasn't worked out my phone number, they can always ask the phone company. My address is required for the ID, voting, and filing taxes. I don't see how the government learns anything from this? Conversely, I would like to believe most companies do not have my government-issued ID, nor a lot of the i…

In this specific case your government can ban you from the web by refusing to verify. E.g. to punish dissidents abroad Belarusian dictatorship simply nullifies their IDs, and lists them as terrorists in public data. Apparently that's enough to ruin somebody's life worldwide. But at least they can use their browsers, which would be not that easy in a world where gov't-backed verification is norm on the net.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#338

Earlier quoted context omitted.

> And you must be signed in. I don't see any mention of that? Google Play services work fine without an account (although if you're the kind of person who doesn't sign in to a Google account on their Android phone, you're probably running a custom ROM or something)

Until now, I have never run "a custom ROM or something", but just the Android that came from the phone vendors and its updates. Nevertheless, I do not have a Google account and I do not intend to have such an account. Of course, this means that I cannot install any app from the official Google store, even if it is a free app. The requirement to login into your Google account should have existed only for payments, not…

You could try aurora store with anonymous accounts, though that has the problem that other people may be able to see the apps you install.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#340
post #325

Earlier quoted context omitted.

Recaptcha contains a whole maximally obfuscated virtual machine with its own bytecode language. It measures your mouse movement, clicks, timing, cadence, hesitation, consistency, tile clicking order, etc. Ambiguous tiles are deliberately placed because the behavior they elicit from humans can be used to discern them from bots.

Yes, the "correct" reaction to the ambiguous tiles is to hover a bit indecisively. You need to waste a certain minimum amount of time on the CAPTCHA. I've found that applying videogame reflexes and zapping all the tiles in a short period of time is a fail, even if they're the correct tiles .

I think it depends on how much it trusts your ip address / user agent. I used to use an extension, nopecha, that would just use ocr and then select all the matching boxes, and it never seemed to get flagged; but I have a lot more trouble on a vpn ip like proton. These days I use buster to solve captchas and it works enough of the time that I don't have to fight with captchas.
Post reply on HN