I was contemplating building a "Scan this QR to verify you're human" for April fools, but then got busy with other things. Wild to see this being built as part of Google reCAPTCHA. I guess we should at least be thankful that we don't have to get our retinas scanned!
Google Cloud fraud defense, the next evolution of reCAPTCHA
441–450 of 467 posts
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#442Earlier quoted context omitted.
Scanning QR in your bank app for payment is near universal in Europe. In fact, it is considered very annoying if a site does not provide the option.
I’m European, never encountered the system you describe. What is it and why does it exist? Apple Pay has been widely available since 2016. Why would anyone want to use some clunky QR-code thing instead?
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#443Earlier quoted context omitted.
Graphene is still tied directly to Android and Pixel devices. It is always at risk. Good luck if Google decides they don’t like the project enough. I went through that nonsense with Canon and magic lantern years ago. Firmware 2.3 was specifically designed to break it on all DSLR’s
Hello! This is Walter Schulz, core team member of the Magic Lantern project and been there back then when Canon introduced firmware 1.3.6 for EOS 5D3. Not sure what you mean by "Firmware 2.3". Let's clear this up: - Canon came up with 1.3.3 to 1.3.5. This disabled in-cam downgrade via Canon Menu. But it was still possible to use EOS Utility's firmware update option to install 1.1.3 or 1.2.3 (or any other version up t…
I was and still am a big fan of the project. I have a t3i still in service because of it. But it is disappointing to receive the tail end of that comment from your account you apparently made just because I gave a quick, flawed example to make a larger point that in no way reflected on your efforts or magic lantern. It was to illustrate how quickly things can go south if a company determines to make it so. Which it sounds like is currently the case with Canon.
Appreciate the clarification nonetheless and have a nice weekend. I know it wasn’t the rudest thing online but for some reason your tone there just kind of got to me. Apologies if it seems like an overreaction. I was a long time admirer of your work so that’s probably why
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#444Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#445Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#446Earlier quoted context omitted.
> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_D…
>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.
When Apple says "Apple Pay is supported on iOS >= $VERSION" they don't explicitly mention that it won't work on jailbroken iPhones, because they don't expect you to make modifications to your device and then try and use their services as normal. This is unsupported and discouraged, just like trying to manually install Google Play services on an OS that didn't ship with it.
The only way to get Google Mobile Services officially is to buy an Android device with it pre-installed while leaving the stock OS untouched. And the only way for an OEM to ship GMS with their device is to certify it with Google. And one of the requirements for certification is to use device attestation keys signed by the Google Hardware Attestation Root certificate [1], thus Play Integrity will pass on all such devices.
[1] https://developer.android.com/privacy-and-security/security-...
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#447Earlier quoted context omitted.
>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.
They said "capable of Play Integrity attestation". It's a weasel statement. If you have GMS, you're capable of performing PIA attestation, you just might fail. So it's strictly true, but doesn't tell us anything about whether it requires PIA.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#448Earlier quoted context omitted.
It's a small computer that I don't really control with a horrible UI, horrible privacy, and nothing but perverse incentives. ("download the app!")
You need LineageOS or GrapheneOS
I researched a phone which should work with lineageOS.
When I received it, I had to find some archaic website and _ask permission_ from a vendor to have the phone unlocked.
From there, I tried to image it from adb and using "guides" (ie, forum posts) and nothing that worked for everyone else ever worked for me.
On paper, installing an aftermarket OS on a phone is not much more difficult than installing an aftermarket OS on a computer. In practice, it's incredibly frustrating and a bit of a crap shoot.
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#449Earlier quoted context omitted.
Some Western European democracies have a well-functioning democracy. The people voting are still humans, a substantial portion votes for racist parties that economically only benefit big corporations and not them, but the damage is limited because there is no winner-takes-all. Everyone has to accept compromises.
> Some Western European democracies have a well-functioning democracy. Which ones?
Say it out loud, don't be shy!
Re: Google Cloud fraud defense, the next evolution of reCAPTCHA
#450Earlier quoted context omitted.
I do. It has downsides of course, but what's the alternative at this point?
I suspect that the HN crowd is somehow insulated from the river of crap and fraud that is the internet experience for a majority of the population.
Also putting QR codes before every webpage doesn't make the web less shitty. It obviously makes it more shitty. And this will 100% be used for fraud. Phishing websites can get away with QR codes now, great.