Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

371–380 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#371
post #248

Earlier quoted context omitted.

> I expect that it will initially not use it it's boiling the frog method. Moving too fast means backlash, but a slow, step by step transition where each step seems reasonable, but ultimately end up with a locked down device, is how they aim to achieve it. And people would be too lazy to complain until the last few steps, by which time it would be too late.

FWIW, “boiling the frog” is the example of false reasoning about slippery slopes (the frog in actuality always left) Your larger point still stands though of normalizing changing expectations by slow degrees

Not really - i would prefer that any policy change that _could_ be utilized in the future to enable future draconian changes be killed before it takes root.

I want a system, like type safety, to guarantee that XYZ cannot be possible, rather than rely on civil jurisprudence and active opposition to prevent it. We don't have that today, but i like to have it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#372

Earlier quoted context omitted.

The thing is even a contact form without something like reCaptcha is doomed on today's web: spam all day.

If it's just a contact form on some random site that isn't particularly valuable to spammers, a bespoke solution like hidden input fields, obfuscation, or some kind of token calculated client-side by JS will probably work just as well.

That used to be the case, unfortuantely today even bespoke solutions can be completed by automation - any anything that just requires running JS in a headless browser was ineffective for a long time already.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#373

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

But what's the alternative to shops strip searching you every time you want to buys something? Shops need a way to prevent looters overwhelming them, and there's no perfect way to distinguish real shoppers from looters.

One solution is to leave a deposit worth more than anything you could loot. What that means in the computing world is those silly browser-based crypto-solvers.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#374

Earlier quoted context omitted.

I will stop using those websites altogether. You know, its funny, I don't think I've ever seen captcha on HN once.

You need one to sign up lately I believe. Which is really all it takes if your identity is required for the captcha and gets associated with your account forevermore.

Tell that to the websites that make you complete a captcha on every login.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#376

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

Europe has very diverse payment systems, you shouldn't be making generalized statements like this.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#377
post #217

I think it’s becoming hard to ignore that the Internet has fundamental flaws from a game theoretical view. I hope that we can skip the step of having Google as the feudal lord who saves us from anarchy though. How about we start with some accountability for entities that host fraud? The main reason we can have relative anonymity in public is part trust and partially because you can get physically taken out if you cro…

> I hope that we can skip the step of having Google as the feudal lord who saves us from anarchy though.

It's clear IMO that this is the plan.

The Google/Meta/Cloudflare axis on the Web is just part of it. Everyone with a nontrivial stake in a major corporation wants techno-feudalism. Every industry is heavily consolidated and is trying to consolidate even more. Lord-and-serf type of arrangements are so prevalent throughout history because they're maximally profitable for the lord and hard to break out of for the serfs.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#378

The constant arms race between bot detection and accessibility is exhausting. I hope this doesn't heavily penalize legitimate users on VPNs.

It will and nobody at Google will care because they don't make money by caring about each individual user.
Post reply on HN