Live data from Hacker News

Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

91–100 of 467 posts

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#93
post #66
post #52

Earlier quoted context omitted.

Many sit-in restaurants enforce QR codes ordering. Started during covid, but keeps happening, especially outside US in my experience.

They don’t enforce in my experience. Just don’t bring a phone and they will bring you a paper menu.

Or if you want to play a bit, have a browser with some extension that breaks websites and show them "it doesn't work on my phone". Pranks apart, in my experience, I always got a paper menu when I asked for it.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#94

Serious question: what if you don’t have a (smart)phone?

That means you're a peasant, and don't matter. Don't worry, they'll work with telecoms and carriers to ensure devices matching your budget are subsidized and made available at every possible opportunity.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#95

I’m trying to use my phone less and less. Ideally I’d like to even switch a dumb phone. But tactics like this will make that nearly impossible if every website starts requiring a QR code scan on a authorized smartphone.

Which means, it's urgent that more and more people realize there are alternative to the everything-on-the-phone situation they live in. And that owning one is not mandatory and should not be (by the way, politicians should also wake up).

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#96

The QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.

Scan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit

I must not be the first one to think of this, right?

Right???

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#97
post #90

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

Where are those ‘mark of the beast’ cranks when you need them?

A few millennia too late for that: the “mark of the beast” is just money — “so that no one could buy or sell unless he had the mark”. How does one buy or sell without money? Otherwise we would call it bartering.

Some currencies are even literally called Marks lol https://en.wikipedia.org/wiki/Mark_(currency)

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#98

Earlier quoted context omitted.

99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.

> press win+R ctrl+V LOL is this real? I guess yes, because yesterday ReCaptcha asked me to screenshot a QR-code with the mobilephone :-D

It is. There are fake Cloudflare CAPTCHAs on pwned Wordpress sites that instruct users to run Powershell scripts.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#99
I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over.

Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet.

Note2: yes, the `curl $URL | bash` installation approach is essentially just that, yet somehow became popular.

Re: Google Cloud fraud defense, the next evolution of reCAPTCHA

#100
post #74

Earlier quoted context omitted.

They will do exactly as it says while also ceaselessly complaining, completely unable to connect their choice to use a website with the pain of using that website. There's some sort of serious issue with learned helplessness or something

It's almost like some people aren't IT hobbyists.

I'm not a heart surgery hobbyist, therefore I don't chop people's chests open, no matter who suggests it.
Post reply on HN