Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

411–420 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#411

I try to keep my phone away from my computer during work to get rid of distractions. OTPs can be done with yubikeys & co., but more and more web services requiring a phone is a step in the wrong direction. Especially since google is using so much tracking, that they can merge tracking data from phone and desktop together.

>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never…

Not really related, but annoying primitive banking authentication flows is why am bullish on stablecoins. I don't need a bank, I'd rather have an open protocol where everybody can design the software and open up competition for wallet implementations.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#412
post #334

Earlier quoted context omitted.

The attestation will include a unique ID of the phone, so that if you get banned you have to keep buying new phones and keep paying money to Google. Google won't stop this because it makes them money. And the official Google OS just won't feature remote-control software.

Or keep stealing IMEI IDs. Now regular people will start getting banned from the internet because of bot activity. You would open your phone one day and see "You have been disconnected from society" and there will be nothing you can do.

It will be cryptographically secure, but you can still pass the captcha code onto a different user so their phone gets banned instead.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#413
post #345

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

What are "bots"? If I use Claude to gather and summarize information for me, is that a "bot"? Because I recently hit that wall and it wasn't great. Turns out in our quest to fight "bots" we also force humans to do the manual labor of copy/pasting information. Why would bots "overwhelm" a site is another discussion — I find it really hard to create a website that would be "overwhelmed" by traffic these days, computers…

> Why would bots "overwhelm" a site is another discussion — I find it really hard to create a website that would be "overwhelmed" by traffic these days, computers are stupidly fast.

are the cloudflare walls really about reducing load? I thought it's because bots are not profitable. They don't click on ads, don't buy, etc.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#414
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previou…

yeah. webpages now load so slow just because i have to wait for the captcha

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#415

Earlier quoted context omitted.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

Right! Let me check the URL before clicking the "confirm your account" link! https://rt434.mjt.lu/lnk/GN2PVLyAIiUHuMqkGcjHkjkcRBtF/zJfB7p... Oh wait, never mind. I guess I won't be signing up for electricity, then? Also, the vast majority of people don't know that google.com and loginto-google.com aren't the same website, or that google.com.securesigning.net isn't real Google. If your device gets busted by opening a…

What's the point of confirmation or user interaction, when nobody knows how to read a URL, and they just click the goddamn accept button?

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#416

Earlier quoted context omitted.

It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.

Whoever told you that is the same person that advocated complex password rules with montly resets and no repeats.

If you really think that's true, I have some QR codes for you to scan.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#417

Earlier quoted context omitted.

Why are you so sure? Have a look at Librem 5 and Pinephone.

I’m familiar with projects like them. I just don’t think any of them are going to break through in a meaningful way anytime soon, if ever. They have very niche markets. I hope they are always an option though.

The prospects for growth are better than ever. GrapheneOS by installer download stats looks to have approximately a quarter of a million users, and the new Motorola partnership should cause that to increase significantly.

If nothing else, it will be a major OEM shipping a non-customer-hostile mobile OS officially for the first time in ages, and Motorola's reach is significant: https://www.androidpolice.com/motorola-razr-drives-foldable-...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#418
post #379

Browser requirements for reCAPTCHA We support the two most recent major versions of the following: desktop (Windows, Linux, Mac) Chrome Firefox Safari Chromium Edge mobile Chrome Safari Android native browser wait where is Firefox for android?

Of course they release this just as alternative browsers like Ladybird are making great progress…

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#419

Earlier quoted context omitted.

I’m familiar with projects like them. I just don’t think any of them are going to break through in a meaningful way anytime soon, if ever. They have very niche markets. I hope they are always an option though.

The prospects for growth are better than ever. GrapheneOS by installer download stats looks to have approximately a quarter of a million users, and the new Motorola partnership should cause that to increase significantly. If nothing else, it will be a major OEM shipping a non-customer-hostile mobile OS officially for the first time in ages, and Motorola's reach is significant: https://www.androidpolice.com/motorola-r…

Graphene is still tied directly to Android and Pixel devices. It is always at risk. Good luck if Google decides they don’t like the project enough. I went through that nonsense with Canon and magic lantern years ago. Firmware 2.3 was specifically designed to break it on all DSLR’s

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#420
I live in a small European country. It's not a shithole, but not on everyone's radar either (we got Google Pay just 3 years ago) and I tried to create a new Google account recently.

It asked me to scan the QR code for verification and I'm guessing it tied that account to my device ID because it opened the Google app and added that new account to my device without my approval.

As a fallback (i.e. no attestation or play services), QR code will send SMS to some short code. Well, it turns out that for my country of a few million people, that number simply does not work on 3/3 mobile providers.

I guess Google just doesn't care anymore if it blocks access to their services or in the OP case, all services that use their services to millions of people if they don't fit a particular profile and have a particular device and agree to have all their internet browsing tied to a static ID that Google controls.

How will this work for iPhone? Doesn't Apple restrict such behavior?

Post reply on HN