Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

451–460 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#451

Earlier quoted context omitted.

I suspect that the HN crowd is somehow insulated from the river of crap and fraud that is the internet experience for a majority of the population.

99% of the crap and fraud comes from ads, aka Google. Thanks, Google. Just run an ad blocker, there goes most of the scams you'll see. Also putting QR codes before every webpage doesn't make the web less shitty. It obviously makes it more shitty. And this will 100% be used for fraud. Phishing websites can get away with QR codes now, great.

> the internet experience for a majority of the population

> Just run an ad blocker,

This reads as "I am fine, so you should be fine". The median internet user has a phone so chock full of cancerous malware.

And if a tool gets good enough to interfere with tech firms ad revenue, they find ways to stop it. See whats happening to ad blockers.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#452
post #345

Earlier quoted context omitted.

But what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.

What are "bots"? If I use Claude to gather and summarize information for me, is that a "bot"? Because I recently hit that wall and it wasn't great. Turns out in our quest to fight "bots" we also force humans to do the manual labor of copy/pasting information. Why would bots "overwhelm" a site is another discussion — I find it really hard to create a website that would be "overwhelmed" by traffic these days, computers…

Do you think the introduction of Anubis on a lot of open source websites was a coincidence. The AI companies' crawling bots don't play by the regular crawling rules and not a good citizen and they are causing a lot of issues. If your Claude session is using the same user agent of their data crawling bot (most of the time it will just check for claude in the user agent) yes you will be classified as bot as well.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#453

Earlier quoted context omitted.

We might need to redo this whole Internet thing because this is insanity.

Maybe it’s time to get in to Ham radio or some other hobby

I'm a licensed ham! Though I've never actually done anything ham-related. I just wanted a license plate with a call sign.

But then I learned that anyone can look up my name and home address from my call sign and decided not to publicly advertise when I'm not home.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#454
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

This is going to make my grapheneos journey a bit more exciting. How wild to force users through an official google identification for web browsing. Does the iPhone recaptcha app force you to login with a Google account? Seems we didn't need ID verification for the web to lose all anonymity.

Another GrapheneOS user here.

Does Play Integrity attestation require the user to be logged in? I wouldn't be surprised but technically it doesn't seem necessary.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#457
post #8

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.

I believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.

s/ensure/gain some confidence/

You can relay bluetooth.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#458
post #57

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

You would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)

You mostly pay by having the vendor scan a QR code on _your_ phone, not the other way around.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#459
post #433

Earlier quoted context omitted.

>don't use it in any capacity? Nope. >You send a lot of letters I guess? [checks own profile] mostly, typewritten. ---- My stockbroker hates my chosen distance. So does my lawyer. So does most family. For most, letters suffice. In my neighborhood I am well respected and known. Everybody else can come visit... or else fuck off . ---- There should be an email/phone platform where you have to pay to contact — and then t…

Love it. You go man. You and I would get on LOL

My mailbox is in userprofile; if you're ever in the area, I'm just down the road.

I don't consider door-knocking rude, but apparently that's not trendy anymore...

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#460
post #54

Earlier quoted context omitted.

I'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files…

I'd rather have no ID verification at all. Give them an inch and they'll take a mile.

What's the alternative though?
Post reply on HN