Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

361–370 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#361
post #196

Earlier quoted context omitted.

Like the Moon or Mars? The power is not something for the people for free.

Some Western European democracies have a well-functioning democracy. The people voting are still humans, a substantial portion votes for racist parties that economically only benefit big corporations and not them, but the damage is limited because there is no winner-takes-all. Everyone has to accept compromises.

> Some Western European democracies have a well-functioning democracy.

Which ones?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#362

Earlier quoted context omitted.

One alternative is to make simple, efficient, and where appropriate even static sites that can scale to meet the demand. The HIBP hashes distribution is a great example.

That doesn't really help if the same Huawei bot keeps re-requesting a bunch of 600 KiB JPEG from 120 rotating IP addresses with random crap at the end of the URL, like what happened to one of my servers. Efficiency doesn't really matter if you're getting hammered by bots. I ended up aggressively IP blocking all of China, Singapore, and a few other East-Asian countries once I noticed that blocking server IP addresses…

Try using anubis. It uses a PoW challenge to make it not make economic sense to scrape websites.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#363
post #325

Earlier quoted context omitted.

Yes, the "correct" reaction to the ambiguous tiles is to hover a bit indecisively. You need to waste a certain minimum amount of time on the CAPTCHA. I've found that applying videogame reflexes and zapping all the tiles in a short period of time is a fail, even if they're the correct tiles .

I think it depends on how much it trusts your ip address / user agent. I used to use an extension, nopecha, that would just use ocr and then select all the matching boxes, and it never seemed to get flagged; but I have a lot more trouble on a vpn ip like proton. These days I use buster to solve captchas and it works enough of the time that I don't have to fight with captchas.

My office uses ZScalar which most sites (especially Cloudflare ones) perceive as an "open proxy". The IP that Z's datacenter uses resolves to some place in Chicago. Some days, no amount of clicking on boxes works for their algorithm.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#364
post #96

Earlier quoted context omitted.

Scan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit I must not be the first one to think of this, right? Right???

Yeah, idiots would fall for it. Both (Google/Apple) need a much higher level of certification for anything to be allowed to be prompted to install. Either you're already big (and can easily afford to pay for some human time to verify), or you're a manufacturer selling something that has an associated app (again, which implies you're reasonably big and can afford to pay for verification.) You're neither? Get lost. Som…

People already complain about the level of control Apple has over apps and you want there to be much more control? That’s never going to happen.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#365

Earlier quoted context omitted.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

But what's the alternative to shops strip searching you every time you want to buys something? Shops need a way to prevent looters overwhelming them, and there's no perfect way to distinguish real shoppers from looters.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#366

I’m trying to use my phone less and less. Ideally I’d like to even switch a dumb phone. But tactics like this will make that nearly impossible if every website starts requiring a QR code scan on a authorized smartphone.

“if every website” is doing a lot of heavy lifting.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#367

Earlier quoted context omitted.

That doesn't really help if the same Huawei bot keeps re-requesting a bunch of 600 KiB JPEG from 120 rotating IP addresses with random crap at the end of the URL, like what happened to one of my servers. Efficiency doesn't really matter if you're getting hammered by bots. I ended up aggressively IP blocking all of China, Singapore, and a few other East-Asian countries once I noticed that blocking server IP addresses…

Try using anubis. It uses a PoW challenge to make it not make economic sense to scrape websites.

Anubis is trivially bypassed by anyone that cares to bypass it. All it does is inconvenience real users with niche/older/extended browsers or those who take basic precautions against tracking and malware.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#369

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

It is far from being universal. And the more annoying part of that is that there are at least 4 incompatible "standards" as to the format of the QRcode.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#370

Feels like we accidentally built a web where proving you’re human now requires approval from 3 different corporations.

I don't think there's much that's accidental about it. The giant corporations with near-monopolies in web-related markets (browsers, search...) are going to be incentivized to put restrictions in place that protect that monopolistic status. As with other facets of life, they can dress up the changes as "protecting users/kids/etc" and mostly get away with it. The same companies are the ones championing the very technologies that make human attestation more and more necessary.
Post reply on HN