Any company that requires me to scan a QR code to make a purchase is losing my purchase.
Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.
Google Cloud fraud defense, the next evolution of reCAPTCHA
421–430 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#422Earlier quoted context omitted.
>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never…
Good on you Curious about email though - do you mean you don't use it for signups/logins etc or you don't use it in any capacity? You send a lot of letters I guess? Sounds like one of those things which sounds impossible to give up but it isn't really
Nope.
>You send a lot of letters I guess?
[checks own profile] mostly, typewritten.
----
My stockbroker hates my chosen distance. So does my lawyer. So does most family. For most, letters suffice.
In my neighborhood I am well respected and known. Everybody else can come visit... or else fuck off.
----
There should be an email/phone platform where you have to pay to contact — and then the receiver can choose to refund payment, if desired.
----
>sounds impossible to give up but it isn't really
I am among the free-est persons I know. Definitely the luckiest. Requires a huge amount of sacrifice and disconnection, but I am rewarded immensely with both.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#423Earlier quoted context omitted.
>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never…
Not really related, but annoying primitive banking authentication flows is why am bullish on stablecoins. I don't need a bank, I'd rather have an open protocol where everybody can design the software and open up competition for wallet implementations.
Bank eradication couldn't come soon enough, IMHO.
>>GENESIS>BLOCK>> "Chancellors on the brink of destruction"...
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#424I don't really get how this stops captcha solving as a service, which is the actual way that scaled recaptcha solving is done? Those things are incredibly cheap and are staffed by humans anyway. Instead of selecting grainy busses, they will just scan the image with their phones.
Google already killed SMS verification market specifically for Google accounts because they reversed the verification from receiving to sending the SMS. Almost a year after, no SMS verification service that made a killing on this is offering an alternative.
So yes, this will definitely affect the captcha solving services.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#425Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#426Earlier quoted context omitted.
The prospects for growth are better than ever. GrapheneOS by installer download stats looks to have approximately a quarter of a million users, and the new Motorola partnership should cause that to increase significantly. If nothing else, it will be a major OEM shipping a non-customer-hostile mobile OS officially for the first time in ages, and Motorola's reach is significant: https://www.androidpolice.com/motorola-r…
Graphene is still tied directly to Android and Pixel devices. It is always at risk. Good luck if Google decides they don’t like the project enough. I went through that nonsense with Canon and magic lantern years ago. Firmware 2.3 was specifically designed to break it on all DSLR’s
But that is a fair concern. While GrapheneOS will continue to support Pixel devices as long as they can, they will not be beholden to Pixel devices once the Motorola partnership is up and running.
They will be beholden to Motorola, instead! But it is a non-exclusive partnership and it sounds like the intention is to move beyond a single OEM. I am hoping that within a few years we see a small number of OEMs all meeting the device requirements GrapheneOS has set, with real consumer choice and more room for the project to maneuver as it sees fit.
In terms of being tied to AOSP, that is a given for the near term. It is still the best option out there and offers the most robust existing ecosystem of apps that has both FOSS options and highly useful closed source options. Major banks are not going to tell Motorola that their customers can't use their banking apps, though I still use 4 or 5 major banking apps on my GrapheneOS devices without issue beyond one bug where it was quickly fixed.
Longer term, an open source hypervisor model sounds like the eventual goal: https://grapheneos.org/faq#roadmap
That will probably happen before modern chipset makers open source their blobs (never?), so I view that as a great compromise that should result in devices that are even more secure, even more private, but still usable by people who live in a society. And it will reduce the dependency on Google significantly as it will give room to non-AOSP apps to run on contemporary hardware with contemporary security.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#427Earlier quoted context omitted.
> Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they? Please don’t respond with sarcasm. Honestly, if you ask such terminally naive questions don't be surprised to get sarcasm in reply. Google does cut off access to chunks of people if it deems it profitable to do so!
It doesn't matter how "naive" you think a question is. Nobody here deserves sarcastic remarks in response to a good-faith question. Literally the first guideline under "In Comments" is: > Be kind. *Don't be snarky.* https://news.ycombinator.com/newsguidelines.html
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#428Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#429Earlier quoted context omitted.
> A site can still choose to have a login system if it wants to. Sites can still rate limit based on IP address or cookies or whatever they use today. So then you don't need either attestation or government IDs, right? > The idea would be to use ZK proofs to demonstrate that "yes, this anonymous request is from a client acting on behalf of an adult human EU citizen" - that's something that is not easy to do today. Bu…
> It's about as plausible as criminals being unable to run their code on a device that can pass attestation. They're both authoritarians with a conflict of interest trying to foist a hellscape on everyone under a pretext their proposal can't even really address. How is the system proposed by GP authoritarian? It's not actually giving away any real PII. We could just argue that it would make Internet less usable for "…
These proposals have two major flaws.
1) They're predicated on a secure implementation, but any government-mandated system is going to be instantaneously ossified. Everyone will have to interface with it and then lobby heavily to prevent it from changing and requiring them to do more work. The initial implementation therefore has to be perfect. Free of not just current but also future vulnerabilities. That has never happened before and isn't likely to. But then you're proposing something with an extremely high probability of permanently compromising everyone's security as required by law.
2) They're structurally authoritarian.
Suppose the initial implementation was actually secure. I can even propose one: Every adult ID has the same QR code on it which you have to scan to be let in. There is no way of distinguishing any of them since they're completely identical even between different IDs, but only the adult IDs have them.
Great, now you just have to scan your ID to be let in. Papers, please. Are ordinary people going to be able to distinguish this from what comes immediately after, when they say the anonymity is causing kids to be let in so they're going to make the QR codes unique, allowing them to track everyone and find out who is lending a kid their ID? Then the infrastructure is already in place. All they have to do is change the implementation out from under you and it's an instant panopticon. Turnkey mass surveillance is authoritarian even if you haven't turned it on yet.
> We could just argue that it would make Internet less usable for "illegal" immigrants who don't have a Gov ID
We're talking about the internet here. People are required to be neither immigrants nor illegal for them to be citizens of another country.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#430Easy for everyday users to deal with, and effective for verifying humans vs bots.
But holy hell, if your phone is a requirement to access sites and you have to go through the security theater like a work device and setting this behavior as a default assumption to have? Ugh. The privacy and security implications of this is quite ugly to think about too, now that Google can link your devices to a stronger degree with this approach.