Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

391–400 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#391

Earlier quoted context omitted.

Which public corporation do you think doesn't hold elections?

Google. The Class B stock setup means Class A shareholders are shouting into a void.

That's still an election.

It's not even Gerrymandering, a company you willingly bought stock from has always had this setup.

Contrast that to most American's experience of their vote just not mattering outside of a few swing states. Having to move across states is such a more drastic requirement than just not buying Google A stock.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#392
This kind of reminds me of these malicious captchas that get you to paste some command into cmd.exe. These kind of captchas will make this situation worse, I could also see some malicious site having a qr code that will download some virus to your phone. QR code captchas are a really bad idea in my opinion.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#393

reCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for…

I think you're spot on. This will block and inconvenience legitimate users while fraudsters have no problem buying more phones. Not a useful direction for real end users.

I doubt they care much about fraud tho, they just care about advertising revenue and bots, people building scams and putting ads on them still produce genuine clicks.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#394
post #351

They think that AI creates conditions that will force humans to use their real IDs. Instead, it will create conditions that people will go offline. I hear much more complaints about surveillance and tracking from Gen-Z than from Millenials. People are waking up. Google already requires you to have a smartphone to create an account, because they want you to scan a QR code even when creating the account on a PC. It wil…

| it will create conditions that people will go offline

| People are waking up

I really hope you're right.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#395
post #245

Like many, I've already trained myself to commit to giving up immediately after the second bus or traffic light or puzzle (some of which I don't even understand anymore). Sounds like my life will not be all that different. Worst case scenario, if this neuters my sovereign and all powerful linux desktop from some critical business I can't avoid (which remains to be seen), it sounds like I will have to have some script…

Kinda off topic question to google - when I do this labour of tagging your data so you let me use the internet - should I click on every box that has parts of the bus? Even if it's like one pixel? Follow up question - why ask people to work when you can just say "pay 1 shmeckel to view this content" and then use this money to pay for data taggers? Thank you for letting me use your internet!

I was pissed off at the same thing today.

I tried ticking every part - not working. Then I tried just the core. Not working. It took me 5 captchas until I got to one that had different images.

Terrible experience. Most of the time I just close the site now as I can't be arsed.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#396

Earlier quoted context omitted.

I have not seen any government adopt such a standard. some EU countries claim to provide anonymous age verification services, but those only hide your identity from the relying party. the site you visited is logged to the government's database along with your identity, before you're redirected to the target site with an "anonymous" token.

> the site you visited is logged to the government's database along with your identity Is that true, or are you spreading FUD? Because the system in question is not even live yet, it's only had experimental releases.

MitID has been active since 2024: https://www.nordicalcohol.org/post/id-now-required-in-denmar...

https://idura.eu/blog/mitid-vs-age-verification-login

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#397

Earlier quoted context omitted.

> the site you visited is logged to the government's database along with your identity Is that true, or are you spreading FUD? Because the system in question is not even live yet, it's only had experimental releases.

MitID has been active since 2024: https://www.nordicalcohol.org/post/id-now-required-in-denmar... https://idura.eu/blog/mitid-vs-age-verification-login

That's not the system I'm talking about: https://ageverification.dev/

> Unlinkability is achieved by design through Zero-Knowledge Proof cryptography see the "Privacy by design" section below.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#398

Earlier quoted context omitted.

Right! Let me check the URL before clicking the "confirm your account" link! https://rt434.mjt.lu/lnk/GN2PVLyAIiUHuMqkGcjHkjkcRBtF/zJfB7p... Oh wait, never mind. I guess I won't be signing up for electricity, then? Also, the vast majority of people don't know that google.com and loginto-google.com aren't the same website, or that google.com.securesigning.net isn't real Google. If your device gets busted by opening a…

> Oh wait, never mind. I guess I won't be signing up for electricity, then? You ~~will~~ should be picking up your phone and calling the electrical company to confirm and to tell them their links are nonsense. Couldn't bother with AI agent on phone, or 60 min waiting queue to a human? Fuck it, don't pay the bill, figure it out later.

This advice sounds like nonsense. CS has neither knowledge of what layers of enterpriseware has wrapped their links, nor the domains that software uses, nor any control over those decisions by software engineering or marketing (or perhaps even more removed, some third-party electricity account management platform that they buy as a service).

You certainly could operate on policies like this, but I think most people prefer to spend their time differently instead of arguing with strangers who don't have any way to solve your problem.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#399

Earlier quoted context omitted.

Do you have an alternate solution? When we hear so many stories from HN'ers of their websites being hammered by out-of-control crawling and fetching and new levels of AI slop spam? This is something site owners choose to implement or not. They're the ones paying the extra hosting fees to handle potentially unwanted traffic, and dealing with spam that traditional CAPTCHA's are no longer effective against. Google's not…

Investigate the anti-bot sellers.

Huh? Investigate for what?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#400
post #128

Earlier quoted context omitted.

But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

IDK about how you scan them, but when I scan one with my camera, I see the top domain part (e.g. it would show 'ycombinator.com' for a link to this page) and have to tap that to open the link. So, that not only satisfies the "can look at" part, but also neutralizes some of the deceptive URL tricks like the ol' `google.com-secure-signin.php-sfd7sdfj.xyz/login.html`.
Post reply on HN