Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

351–360 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#351
They think that AI creates conditions that will force humans to use their real IDs. Instead, it will create conditions that people will go offline.

I hear much more complaints about surveillance and tracking from Gen-Z than from Millenials. People are waking up.

Google already requires you to have a smartphone to create an account, because they want you to scan a QR code even when creating the account on a PC. It will get worse.

The solution is not to use YouTube but Rumble instead.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#352
post #269
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

And you must be signed in. I frequently get flagged as suspicious activity and have to pass a captcha when trying to use the Google verbatim search function on a signed out Firefox browser on android.

I get this all the time with Brave, and especially in Private Windows. It's the number one reason I don't use Google Search anymore. I've used Brave search for a while, what do you use? Do you have a way to prevent the captchas?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#353
post #325

Earlier quoted context omitted.

Yes, the "correct" reaction to the ambiguous tiles is to hover a bit indecisively. You need to waste a certain minimum amount of time on the CAPTCHA. I've found that applying videogame reflexes and zapping all the tiles in a short period of time is a fail, even if they're the correct tiles .

I think it depends on how much it trusts your ip address / user agent. I used to use an extension, nopecha, that would just use ocr and then select all the matching boxes, and it never seemed to get flagged; but I have a lot more trouble on a vpn ip like proton. These days I use buster to solve captchas and it works enough of the time that I don't have to fight with captchas.

Is buster a browser extension?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#354
post #289

Earlier quoted context omitted.

In said US of America, when the government wants to know something about you, they will get everything they want from the companies - it's even written clearly in the US laws. So I'm not sure why (or where) you draw that line...

1. if they have to subpoena each site each time they need user data, it reduces mass surveillance risk. I'm okay with cops getting a warrant to access someone's gmail. I'm not okay requiring everyone to use email.gov. 2. I use a VPN and pseudonyms. they could unmask me if they cared to, but it'd be annoying. it'd be a lot more annoying if they wanted to unmask every VPN user all the time.

Being available as part of Google Cliud means subpoenaing Google is probably sufficient for most web sites.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#355

Earlier quoted context omitted.

I think it depends on how much it trusts your ip address / user agent. I used to use an extension, nopecha, that would just use ocr and then select all the matching boxes, and it never seemed to get flagged; but I have a lot more trouble on a vpn ip like proton. These days I use buster to solve captchas and it works enough of the time that I don't have to fight with captchas.

Is buster a browser extension?

Yes: https://github.com/dessant/buster

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#356
post #248

Earlier quoted context omitted.

> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…

> I expect that it will initially not use it it's boiling the frog method. Moving too fast means backlash, but a slow, step by step transition where each step seems reasonable, but ultimately end up with a locked down device, is how they aim to achieve it. And people would be too lazy to complain until the last few steps, by which time it would be too late.

FWIW, “boiling the frog” is the example of false reasoning about slippery slopes (the frog in actuality always left)

Your larger point still stands though of normalizing changing expectations by slow degrees

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#357
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

Yep.

I learned yesterday you can’t sign in to Cursor on Brave Browser. Had to switch to Safari. This is only going to become more and more common.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#358

Serious question: what if you don’t have a (smart)phone?

I shuddered when I realized that Google would require (smart)phones for recaptcha. I say this because I used to have a dumb-phone for an year and more and I only stopped using it when it broke (its battery fried but its replacable but I don't find battery its size). No smart-phone period,(I am a teen so I can afford to do that) Recently, I wanted to make a google account, guess-what, I literally couldn't make a googl…

If you make a blog post, make sure to also comment on how the audio reCAPTCHAs are nearly impossible and are blocked on public VPNs. The visual reCAPTCHAS have vauge instructions (they say “Select all squares with busses.” when they mean “Select all squares that have a bus or part of a bus and do not select any other squares.”. For 2 years I could not figure that out so I had to use the audio captchas but then Google blocked them on public VPNs and also made them almost impossible. I could only figure that out when Google Gemini clarified it for me.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#359
post #248

Earlier quoted context omitted.

> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…

> I expect that it will initially not use it it's boiling the frog method. Moving too fast means backlash, but a slow, step by step transition where each step seems reasonable, but ultimately end up with a locked down device, is how they aim to achieve it. And people would be too lazy to complain until the last few steps, by which time it would be too late.

There is already so much backlash. If I ever use a recaptcha, I will have Google Gemini solve it wasting Googles compute and messing up the dataset.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#360

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

PoW challenges that make bots not viable.
Post reply on HN