Live data from Hacker News

Google Cloud Fraud Defence is just WEI repackaged

privatecaptcha.com

381–390 of 394 posts

Re: Google Cloud Fraud Defence is just WEI repackaged

#381
post #312

Earlier quoted context omitted.

>Proof of identity in theory can solve the problem but at the cost of privacy. All current implementations: yes. I do think there are some privacy preserving solutions, but they're obviously imperfect. But assuming you have a central authority that can validate and sign valid government identification, it seems like some sort of ZK scheme could allow one to verify that they have a valid government issued ID, but with…

From what I've seen no such solution guarantees privacy to the user if the signing body (or the government) and the website collude to deanonymize the user.

What if the the government signs your private key but doesn't store the list of people who requested this?

Re: Google Cloud Fraud Defence is just WEI repackaged

#382

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

https://news.ycombinator.com/item?id=48068322

Re: Google Cloud Fraud Defence is just WEI repackaged

#383

Earlier quoted context omitted.

In what area is there no real competition? I can think of real competition in everything Google does with the possible exception of YouTube.

Everything that gets money from ads. The network effects are too strong for competition against their ads platform and their ability to do targeted advertising based on data only they have. You can’t build a new ads platform and then use that to monetize your company’s other services, because the existing ad networks are so mature and established. Phones. Your choice is Apple or Google. As you said, YouTube. Again, t…

> Phones. Your choice is Apple or Google.

This is false. Sent from my Librem 5.

Re: Google Cloud Fraud Defence is just WEI repackaged

#384

I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clea…

> people can be bribed or convinced to join botnets so IP whitelisting doesn't work either what does that bribe look like, as in, how much can one get? what all does that entail? is that a little box i connect to my network and forget about? does that mean if i unplug it unless another payment is received that will work out? i'm asking for a friend that's looking to avoid selling plasma to make ends meet.

https://www.honeygain.com/ for example (it’s really not that much money though)

Re: Google Cloud Fraud Defence is just WEI repackaged

#385

Earlier quoted context omitted.

Chrome has gone off doing their own standards to some extent, but you're forgetting what it was like when Internet Explorer dominated. You basically couldn't use the web without IE because they broke so many standards and implemented them in closed source. Then there was ActiveX on top, straight up Windows binaries in web. And besides there being a dominant engine, only one browser could use that engine. Trading that…

I just got a Docusign and it didn't work in Firefox, I had to use Chrome. That's a huge blow right there. (I sent negative feedback about this to Docusign.)

I vaguely remember running into that too a few times, strangely not on every doc. Also one particular part of the Chase mortgage website.

Re: Google Cloud Fraud Defence is just WEI repackaged

#386

Earlier quoted context omitted.

> You don't think that some people simply disagree with the idea that this is bad? Where are they? Where? Can you point me to one person in this thread who "disagrees with the idea that this is bad"? Apparently even you don't go that far.

Me. I think the idea is sad and tragic , but also that we are at the point where we have no choice but to do something. AI/LLM's have created a vector for abuse that previous tools are failing to protect against, and the problem is only getting worse. I'm sick of the increase of LLM slop on websites in comments and posts. I'm sick of how fraud and spam and abuse can be increasingly automated in ways current tools can…

[deleted]

Re: Google Cloud Fraud Defence is just WEI repackaged

#387

Earlier quoted context omitted.

> You don't think that some people simply disagree with the idea that this is bad? Where are they? Where? Can you point me to one person in this thread who "disagrees with the idea that this is bad"? Apparently even you don't go that far.

Me. I think the idea is sad and tragic , but also that we are at the point where we have no choice but to do something. AI/LLM's have created a vector for abuse that previous tools are failing to protect against, and the problem is only getting worse. I'm sick of the increase of LLM slop on websites in comments and posts. I'm sick of how fraud and spam and abuse can be increasingly automated in ways current tools can…

>I don't realistically see any alternative but for some kind of reliable signal that a web request is most likely coming from a real person (not a perfect guarantee, but something good enough). Which means some kind of attestation that it's a real hardware device that costs at least a few bucks and is making human-level numbers of requests (not millions per day), or else some kind of digital ID attestation system.

After years and years of looking, a problem for which cryptocurrency is the perfect solution has been found.

Oh wait, Hashcash is kind of how we got cryptocurrency in the first place.

But yes, let's pretend that much less creepy forms of attestation aren't a solved problem and figure out how we can introduce more avenues for surveillance.

Re: Google Cloud Fraud Defence is just WEI repackaged

#388

Earlier quoted context omitted.

I hate this trite and the managers that say "don't bring me problems, bring me solutions" nonsense. I'm not the person to be able to fix it so the solution is make the problem known so others responsible can fix it. If I could fix it, I wouldn't be telling you about the problem. If anything, I would tell you how I fixed an issue in some stand up or other of the many meetings scheduled keeping me from working.

I am only aware of two solutions: 1) proof of identity, tying accounts to real-world things that are hard or impossible to replicate 2) proof of work, tying accounts or actions to the ability to run computations Proof of identity in theory can solve the problem but at the cost of privacy. Proof of work can be defeated but has the possibility of preserving privacy.

Why are you skipping entirely over good old legislation and law enforcement against offenders, including diplomatic pressure for foreign offenders.

Not everything calls for a purely technical solution.

Re: Google Cloud Fraud Defence is just WEI repackaged

#389

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

Oh so you don't like wearing a tracking device around your ankle 24/7? Than what's YOUR solution to organized crime? Huh???

Re: Google Cloud Fraud Defence is just WEI repackaged

#390

Given all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?

Oh so you don't like wearing a tracking device around your ankle 24/7? Than what's YOUR solution to organized crime? Huh???

[deleted]
Post reply on HN