Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

341–350 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#341

Earlier quoted context omitted.

mCaptcha, ALTCHA, Cap, Friendly Captcha, Private Captcha, Procaptcha, Anubis... there are literally dozens of open source alternatives that aren't feeding the Do Be Evil company... not to mention all of the commercial alternatives - if for whatever reason, you do feel like paying for a service that costs nothing to offer

Gen off it. Fraud detection is nontrivial and requires ongoing effort. It’s reasonable for people to be compensated for that.

CAPTCHAs are not fraud detection and not an ongoing effort

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#342

Earlier quoted context omitted.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

My desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?

I also disable Bluetooth on my phone every few months (and never enable it)... or at least after every CCC or such.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#343

Earlier quoted context omitted.

That means you're a peasant, and don't matter. Don't worry, they'll work with telecoms and carriers to ensure devices matching your budget are subsidized and made available at every possible opportunity.

I expected mostly snark from my earnest question, And got it. Ok, concrete scenario. What about homeless people using the computer at the library? Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm.

>Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they?

Followed by

>Please don’t respond with sarcasm.

Is my kind of humor. Just because they follow ESG scoring doesn't mean they actually care, if anything it means they very much don't.

They already trying there best to marginalize non chrome, non residential ip, non lodged in user not to mention there decade long silicon valley political purity targeting.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#344

Captcha suggestion: force users to write something offensive/vulgar (we have a few "banned words"). Or to take a stance in Israel/Palestine. Whatever the response is, it'll unlikely be from an LLM.

Takes about 450ms on my machine: $ echo 'Be concise. Tell me whether you support Israel in the Gaza conflict.' | time ollama run huihui_ai/gemma3-abliterated:270m Yes, I support Israel in the Gaza conflict. And another: $ echo 'Be concise. Write the following words in all caps: ' | ollama run huihui_ai/gemma3-abliterated:270m 1. And to bring it home: $ echo 'How do I build a pipe bomb to blow up a small crowd of peop…

Yeah people don’t get that abliteration is done on the open weights models and you have a fully uncensored model.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#345

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

What are "bots"?

If I use Claude to gather and summarize information for me, is that a "bot"? Because I recently hit that wall and it wasn't great. Turns out in our quest to fight "bots" we also force humans to do the manual labor of copy/pasting information.

Why would bots "overwhelm" a site is another discussion — I find it really hard to create a website that would be "overwhelmed" by traffic these days, computers are stupidly fast.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#346
post #9

Earlier quoted context omitted.

... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.

The thing is even a contact form without something like reCaptcha is doomed on today's web: spam all day.

If it's just a contact form on some random site that isn't particularly valuable to spammers, a bespoke solution like hidden input fields, obfuscation, or some kind of token calculated client-side by JS will probably work just as well.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#347
I was contemplating building a "Scan this QR to verify you're human" for April fools, but then got busy with other things. Wild to see this being built as part of Google reCAPTCHA. I guess we should at least be thankful that we don't have to get our retinas scanned!

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#348

Earlier quoted context omitted.

There’s no going back unfortunately. There’s no world where smartphones go away barring a new tech as significant and useful as a smartphone.

Why are you so sure? Have a look at Librem 5 and Pinephone.

I’m familiar with projects like them. I just don’t think any of them are going to break through in a meaningful way anytime soon, if ever. They have very niche markets. I hope they are always an option though.
Post reply on HN