Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

401–410 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#401
post #275

Earlier quoted context omitted.

From an American perspective, i don't trust the government with the implementation details, nor do I trust our political climate, misaligned incentives, and general disinterest in good governance to implement something so sensitive. If I lived in say, Sweden, I feel much more comfortable trusting their government to implement. In America, I feel I must always vote in a way that prevents giving any power to the govern…

the grass is always greener on the other side

You think people in Nordic countries think they'd be able to trust their government more if they were American?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#402
post #351

They think that AI creates conditions that will force humans to use their real IDs. Instead, it will create conditions that people will go offline. I hear much more complaints about surveillance and tracking from Gen-Z than from Millenials. People are waking up. Google already requires you to have a smartphone to create an account, because they want you to scan a QR code even when creating the account on a PC. It wil…

I would really like to see a renaissance of in-person activities. I think a big hurdle to this though is the lack of a 3rd place for communities to exist. Parks are nice in the summer but less ideal in the winter (and not available in all neighborhoods). Town squares are also more hostile to "loiterers" (no data to back this just feelingss).

Overall I think if we want to see a resurgence of IRL, we need the social support of our governing bodies which imo is a large hill to climb.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#403
post #275

Earlier quoted context omitted.

the grass is always greener on the other side

You think people in Nordic countries think they'd be able to trust their government more if they were American?

OP never lived in Europe and is looking through rose-colored glasses.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#404

Earlier quoted context omitted.

Let's play this out: how do you determine individual clients? By ip? By seasionid?

How do you "determine" individual clients to show them CAPTCHAs? Yes, you can, and probably should, make some use of IP addresses, although that would work better if idiots hadn't polluted the Internet with quite so much NAT. But you don't have to, and you definitely don't have to completely rely on it. Look for a cookie. If you don't see it, route the client through a page that sets it. Yes, this is subject to flood…

> How do you "determine" individual clients to show them CAPTCHAs?

Cookies.

> Yes, this is subject to flooding attacks

Err... Yeah exactly.

> in exactly the same way that every CAPTCHA system is subject to flooding attacks.

Uhm no the whole point of captchas is that it requires (or used to anyway) humans to solve them, thus limiting the rate to human speeds.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#405

I try to keep my phone away from my computer during work to get rid of distractions. OTPs can be done with yubikeys & co., but more and more web services requiring a phone is a step in the wrong direction. Especially since google is using so much tracking, that they can merge tracking data from phone and desktop together.

>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never…

[dead]

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#408

Earlier quoted context omitted.

How do you "determine" individual clients to show them CAPTCHAs? Yes, you can, and probably should, make some use of IP addresses, although that would work better if idiots hadn't polluted the Internet with quite so much NAT. But you don't have to, and you definitely don't have to completely rely on it. Look for a cookie. If you don't see it, route the client through a page that sets it. Yes, this is subject to flood…

> How do you "determine" individual clients to show them CAPTCHAs? Cookies. > Yes, this is subject to flooding attacks Err... Yeah exactly. > in exactly the same way that every CAPTCHA system is subject to flooding attacks. Uhm no the whole point of captchas is that it requires (or used to anyway) humans to solve them, thus limiting the rate to human speeds.

> Uhm no the whole point of captchas is that it requires (or used to anyway) humans to solve them, thus limiting the rate to human speeds.

The CAPTCHA challenge page itself has to be served to a client that has not yet given any evidence that it's not a bot. It's just as expensive to serve the challenge page as it is to serve a cookie-setting page. Bots can infinitely retrieve the challenge page (and can also infinitely try to retrieve the underlying "authenticated" page, forcing you to process redirects).

The only reason it looks better to you is that a third party is serving the CAPTCHA. You could also have a third party serve the cookie-setting page.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#409

I try to keep my phone away from my computer during work to get rid of distractions. OTPs can be done with yubikeys & co., but more and more web services requiring a phone is a step in the wrong direction. Especially since google is using so much tracking, that they can merge tracking data from phone and desktop together.

>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never…

Good on you

Curious about email though - do you mean you don't use it for signups/logins etc or you don't use it in any capacity? You send a lot of letters I guess?

Sounds like one of those things which sounds impossible to give up but it isn't really

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#410
post #403

Earlier quoted context omitted.

You think people in Nordic countries think they'd be able to trust their government more if they were American?

OP never lived in Europe and is looking through rose-colored glasses.

Sometimes your grass is just yellow.
Post reply on HN