Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

381–390 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#381

Earlier quoted context omitted.

Rate limit individual clients.

Let's play this out: how do you determine individual clients? By ip? By seasionid?

How do you "determine" individual clients to show them CAPTCHAs? Yes, you can, and probably should, make some use of IP addresses, although that would work better if idiots hadn't polluted the Internet with quite so much NAT.

But you don't have to, and you definitely don't have to completely rely on it. Look for a cookie. If you don't see it, route the client through a page that sets it.

Yes, this is subject to flooding attacks... in exactly the same way that every CAPTCHA system is subject to flooding attacks. But it actually uses fewer resources per request than showing the CAPTCHA would.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#382

reCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for…

Often illegitimate users don't even have to solve the captcha because whenever one shows up they can just trash the session and start over fresh. As long as they get to the desired result often enough they're golden. Not so for real users who only have one account on one or at most a handful of browsers.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#383

Earlier quoted context omitted.

That means you're a peasant, and don't matter. Don't worry, they'll work with telecoms and carriers to ensure devices matching your budget are subsidized and made available at every possible opportunity.

I expected mostly snark from my earnest question, And got it. Ok, concrete scenario. What about homeless people using the computer at the library? Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm.

It's unpleasant to face, but this initiative from Google is a concrete example that the homeless/too-poor-for-phone do not matter. I've heard of cases where university library apps/admin systems required a phone, and for those cases you could borrow a phone from a "device library" on campus. But, obviously, there's nothing like this for the homeless guy being blocked by Google...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#384

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

PoW challenges that make bots not viable.

You mean a la Anubis? But people also seem unhappy with that; and in any case Anubis is designed to stop ai crawlers; it doesn't work against a targeted crawler or a targeted dos attack.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#385

Earlier quoted context omitted.

Illegal immigrants =/= marginalized people

No person is illegal

You might want to campaign to get rid of the entire concept of citizenship then. Until you manage to get people onboard with that, the lawful thing to do is to support legal enforcement of the laws on the book, which most people also agree with in this case.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#386
post #371

Earlier quoted context omitted.

FWIW, “boiling the frog” is the example of false reasoning about slippery slopes (the frog in actuality always left) Your larger point still stands though of normalizing changing expectations by slow degrees

Not really - i would prefer that any policy change that _could_ be utilized in the future to enable future draconian changes be killed before it takes root. I want a system, like type safety, to guarantee that XYZ cannot be possible, rather than rely on civil jurisprudence and active opposition to prevent it. We don't have that today, but i like to have it.

So you want to ship technical means that prohibit companies from shipping products that limit what you can do with them?

It’s kind of self-defeating, isn’t it? Why would I adopt your standard when it limits what I can build?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#387

Earlier quoted context omitted.

PoW challenges that make bots not viable.

You mean a la Anubis? But people also seem unhappy with that; and in any case Anubis is designed to stop ai crawlers; it doesn't work against a targeted crawler or a targeted dos attack.

People are unhappy with Anubis because it's not designed to stop "AI crawlers", despite marketing as such. It's designed to stop DDoS attacks on layer 7. Anyone who pays the computing-fee gets to pass, regardless of species.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#388

Earlier quoted context omitted.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

Right! Let me check the URL before clicking the "confirm your account" link! https://rt434.mjt.lu/lnk/GN2PVLyAIiUHuMqkGcjHkjkcRBtF/zJfB7p... Oh wait, never mind. I guess I won't be signing up for electricity, then? Also, the vast majority of people don't know that google.com and loginto-google.com aren't the same website, or that google.com.securesigning.net isn't real Google. If your device gets busted by opening a…

> Oh wait, never mind. I guess I won't be signing up for electricity, then?

You ~~will~~ should be picking up your phone and calling the electrical company to confirm and to tell them their links are nonsense. Couldn't bother with AI agent on phone, or 60 min waiting queue to a human? Fuck it, don't pay the bill, figure it out later.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#389

I try to keep my phone away from my computer during work to get rid of distractions. OTPs can be done with yubikeys & co., but more and more web services requiring a phone is a step in the wrong direction. Especially since google is using so much tracking, that they can merge tracking data from phone and desktop together.

>more and more web services requiring a phone is a step in the wrong direction

Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?").

I legitimately have never scanned a QR code, have never Zoomed, don't even own a phone anymore, and stopped using email many years ago.

Really hoping Yubikey becomes widely accepted at US banks/CUs, soon.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#390
post #245

Like many, I've already trained myself to commit to giving up immediately after the second bus or traffic light or puzzle (some of which I don't even understand anymore). Sounds like my life will not be all that different. Worst case scenario, if this neuters my sovereign and all powerful linux desktop from some critical business I can't avoid (which remains to be seen), it sounds like I will have to have some script…

Kinda off topic question to google - when I do this labour of tagging your data so you let me use the internet - should I click on every box that has parts of the bus? Even if it's like one pixel? Follow up question - why ask people to work when you can just say "pay 1 shmeckel to view this content" and then use this money to pay for data taggers? Thank you for letting me use your internet!

There's no specific "right" answer on the boxes. Like another post said they're looking at god-knows-what to decide whether or not to let you load the website.

Years ago I started to deliberately pick one or two wrong answers, or just not take the time to really look at them, and it made no discernible difference on how often I pass.

Post reply on HN