Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

441–450 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#441
post #347

I was contemplating building a "Scan this QR to verify you're human" for April fools, but then got busy with other things. Wild to see this being built as part of Google reCAPTCHA. I guess we should at least be thankful that we don't have to get our retinas scanned!

That's next; Sam Altman's Worldcoin is now pivoting to identity verification.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#442

Earlier quoted context omitted.

Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.

I’m European, never encountered the system you describe. What is it and why does it exist? Apple Pay has been widely available since 2016. Why would anyone want to use some clunky QR-code thing instead?

[deleted]

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#443

Earlier quoted context omitted.

Graphene is still tied directly to Android and Pixel devices. It is always at risk. Good luck if Google decides they don’t like the project enough. I went through that nonsense with Canon and magic lantern years ago. Firmware 2.3 was specifically designed to break it on all DSLR’s

Hello! This is Walter Schulz, core team member of the Magic Lantern project and been there back then when Canon introduced firmware 1.3.6 for EOS 5D3. Not sure what you mean by "Firmware 2.3". Let's clear this up: - Canon came up with 1.3.3 to 1.3.5. This disabled in-cam downgrade via Canon Menu. But it was still possible to use EOS Utility's firmware update option to install 1.1.3 or 1.2.3 (or any other version up t…

With all due respect, this event was literally over a decade ago so yes I apologize that I got some numbers/info wrong, but the light derision at the end is unnecessary. I distinctly remember the firmware update they did making it so you couldn’t boot magic lantern on the 5d3 which caused a problem for us on a shoot where we had the raw pipeline ready to go. I thought it was broader. Clearly my memory is mistaken, I was just using an example that I (apparently incorrectly) recalled. https://www.eoshd.com/news/canon-blocking-magic-lantern-late...

I was and still am a big fan of the project. I have a t3i still in service because of it. But it is disappointing to receive the tail end of that comment from your account you apparently made just because I gave a quick, flawed example to make a larger point that in no way reflected on your efforts or magic lantern. It was to illustrate how quickly things can go south if a company determines to make it so. Which it sounds like is currently the case with Canon.

Appreciate the clarification nonetheless and have a nice weekend. I know it wasn’t the rudest thing online but for some reason your tone there just kind of got to me. Apologies if it seems like an overreaction. I was a long time admirer of your work so that’s probably why

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#444
So I can't browse the web with just one device? Forget which device they want me to have or any other of the million absurd insults of this plan, I feel like the most insane part is expecting everyone to have two devices with battery and internet at all times.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#446

Earlier quoted context omitted.

> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…

>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.

It indeed runs on modified versions of Android, but this is not supported by Google and never has been.

When Apple says "Apple Pay is supported on iOS >= $VERSION" they don't explicitly mention that it won't work on jailbroken iPhones, because they don't expect you to make modifications to your device and then try and use their services as normal. This is unsupported and discouraged, just like trying to manually install Google Play services on an OS that didn't ship with it.

The only way to get Google Mobile Services officially is to buy an Android device with it pre-installed while leaving the stock OS untouched. And the only way for an OEM to ship GMS with their device is to certify it with Google. And one of the requirements for certification is to use device attestation keys signed by the Google Hardware Attestation Root certificate [1], thus Play Integrity will pass on all such devices.

[1] https://developer.android.com/privacy-and-security/security-...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#447
post #140

Earlier quoted context omitted.

>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.

They said "capable of Play Integrity attestation". It's a weasel statement. If you have GMS, you're capable of performing PIA attestation, you just might fail. So it's strictly true, but doesn't tell us anything about whether it requires PIA.

No, they were correct in their understanding of what I meant. I should've said "capable of passing Play Integrity's device attestation checks". I replied to them with more context.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#448

Earlier quoted context omitted.

It's a small computer that I don't really control with a horrible UI, horrible privacy, and nothing but perverse incentives. ("download the app!")

You need LineageOS or GrapheneOS

I went down this path once.

I researched a phone which should work with lineageOS.

When I received it, I had to find some archaic website and _ask permission_ from a vendor to have the phone unlocked.

From there, I tried to image it from adb and using "guides" (ie, forum posts) and nothing that worked for everyone else ever worked for me.

On paper, installing an aftermarket OS on a phone is not much more difficult than installing an aftermarket OS on a computer. In practice, it's incredibly frustrating and a bit of a crap shoot.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#449

Earlier quoted context omitted.

Some Western European democracies have a well-functioning democracy. The people voting are still humans, a substantial portion votes for racist parties that economically only benefit big corporations and not them, but the damage is limited because there is no winner-takes-all. Everyone has to accept compromises.

> Some Western European democracies have a well-functioning democracy. Which ones?

+1

Say it out loud, don't be shy!

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#450

Earlier quoted context omitted.

I do. It has downsides of course, but what's the alternative at this point?

I suspect that the HN crowd is somehow insulated from the river of crap and fraud that is the internet experience for a majority of the population.

99% of the crap and fraud comes from ads, aka Google. Thanks, Google. Just run an ad blocker, there goes most of the scams you'll see.

Also putting QR codes before every webpage doesn't make the web less shitty. It obviously makes it more shitty. And this will 100% be used for fraud. Phishing websites can get away with QR codes now, great.

Post reply on HN