14 ms·
Google Cloud fraud defense, the next evolution of reCAPTCHA
- SoKamil 5mo agoGoogle clearly wants only Google approved models to traverse the web.
- jcfrei 5mo agoThey only want dumb humans doing the shopping not some hyper-focused bot that wont add any extra items into the shopping cart.
- stupidgeek314 5mo agoWhy can't an AI scan the QR code? Just fire up an emulator if necessary
- tardedmeme 5mo agoThe app that scans the code talks to the TPM in your phone to prove that your phone is running an unmodified Google OS.
- themafia 5mo agoWhich would be meaningful if phones weren't remotely controllable. So the net effect is every AI agent will also have and connect to a physical phone.
- tardedmeme 5mo agoThe attestation will include a unique ID of the phone, so that if you get banned you have to keep buying new phones and keep paying money to Google. Google won't stop this because it makes them money. And the official Google OS just won't feature remote-control software.
- lucb1e 5mo agoThere's also remote control hardware (a printer-like device can operate a touchscreen). But the first point stands, yes. Be it a phone or another hardware attestation device, they and Apple will be giving "I am human, let me participate in society" checkmarks out, directly or indirectly for money
- Asooka 4mo agoOr keep stealing IMEI IDs. Now regular people will start getting banned from the internet because of bot activity. You would open your phone one day and see "You have been disconnected from society" and there will be nothing you can do.
- tardedmeme 4mo agoIt will be cryptographically secure, but you can still pass the captcha code onto a different user so their phone gets banned instead.
- Hizonner 5mo ago... which is why you'll get locked out if you happen to visit an unusual number of sites in a day.
- duskdozer 4mo agoOne can expect it will be tied to a government ID, at which point they ban you from the internet if you disobey them.
- hellojesus 5mo agoI know that's the final destination, but I didn't see that listed in the requirements page linked above. Any proof of this affecting the current implementation?
- postalrat 5mo agoSo openclaw or whatever future software will run or control unmodified google os devices.
- nerdsniper 5mo agoBluetooth is generally used to prove that the two devices are co-located, which makes it more complex to do your proposed kind of deployment at-scale. Bespoke solutions could perhaps work around for some smaller number of devices, this QR code layer by itself isn't intended to stop 100% of workarounds.
- halapro 5mo agoNo browser supports Bluetooth.
- LoganDark 5mo agoChrome does...
- drusepth 5mo agoInterestingly, only on desktop/Android and not iOS it seems.
- LoganDark 5mo agoChrome on iOS uses WebKit, so that makes sense. (*I think in the EU, iOS Chrome can use Blink, but I am not sure if it actually does.)
- halapro 4mo agoThat's news to me https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetooth_API https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetoo... Websites cannot use Bluetooth anywhere. The QR codes shown in the blog post are not passkey QR codes, which is likely what's confusing you.
- nerdsniper 5mo agoThese passkey QR codes don't need to use Web Bluetooth API, because they utilize the WebAuthn API. The website itself isn't given access to the bluetooth, the task is handed off to the browser, which as a native application, can access bluetooth and abstracts the bluetooth away.
- xacky 5mo agoThe fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.
- dredmorbius 5mo agoWhere is this specified? I don't see that in TFA.
- skinfaxi 5mo agoI think they are jumping ahead but it does seem like a logical conclusion. Would tie in nicely with the online ID verification stuff popping up everywhere.
- luma 5mo agoThe example they give in TFA is having the user scan a QR code, presumably from a mobile device.
- bryan_w 5mo agoBut that's not a specification
- charcircuit 5mo agoDoes anybody trust it? MacOS seems to be the only desktop platform I see be trusted.
- pixelmelt 5mo agoIm in the community reverse engineering web CAPTCHAs, it's because they are too easy to reverse engineer with Claude now. I've seen multiple people break botguard (the obfuscation used by recapcha) within the last year when before it was considered a huge technical envour. Devices like phones don't have this issue since Google owns the client attestation end to end and can fingerprint you without the risk of receiving spoofed values.
- dangus 5mo ago
- mayama 5mo agoThe site doesn't mention this. But, are they locking down QR code auth for only safetynet authenticated devices and with mobile number verification?
- bobbiechen 5mo agoYeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms). But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.
- Hizonner 5mo ago... You... think... it would be a good thing. Don't you...
- IshKebab 5mo agoI do. It has downsides of course, but what's the alternative at this point?
- intended 5mo agoI suspect that the HN crowd is somehow insulated from the river of crap and fraud that is the internet experience for a majority of the population.
- array_key_first 4mo ago99% of the crap and fraud comes from ads, aka Google. Thanks, Google. Just run an ad blocker, there goes most of the scams you'll see. Also putting QR codes before every webpage doesn't make the web less shitty. It obviously makes it more shitty. And this will 100% be used for fraud. Phishing websites can get away with QR codes now, great.
- arian_ 5mo agoGoogle building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.
- tardedmeme 5mo agoThey're expecting everyone to whitelist Google agents because Google has the market share for people to complain if Google agents don't work.
- throwaway67743 5mo agoWith the apparent competence that built Gemini, I have zero faith in Google building or doing anything that works anymore.
- throwaway67743 5mo agoTo counter the idiot downvotes, I proffer this as a prime example of Gemini: Resolving Final Compilation Conflict: I will remove the redundant `Entry` type declaration to resolve the compilation conflict and finalize the in-memory `StdNetDB` refactor. Edit std.go → Accepted (+0, -1) 31 type Entry struct { 32 RouterInfo *router_info.RouterInfo 33 } 34 - 34 func NewStdNetDB(db string) *StdNetDB { 35 ctx, cancel := context.WithCancel(context.Background()) 36 return &StdNetDB{ That and the cli keeps exiting 0, without hinting why... Quality like the "AI Overview" that hijacks an entire page and isn't even relevant to the search terms - uBlock still doing god's work. It made me realise I was perhaps a bit hard on Claude (but then it did something equally as dumb)
- mandeepj 5mo agoPoint On! Probably done by two different teams, who don't know about each other. I hate this (re)captcha so bad. They assume everyone is bad.
- Analemma_ 5mo agoIt’s the same thing with Sam Altman and Worldcoin: create the problem, then sell people the solution (which also just so happens to shred more privacy). Play both sides and profit; it’s great work if you can get it.
- bramhaag 5mo agoThe requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 https://support.google.com/recaptcha/answer/16609652 So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future. No mention of device integrity verification yet, but the writing is on the wall.
- Hizonner 5mo ago... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.
- tardedmeme 5mo ago99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.
- mrguyorama 5mo agoThey will do exactly as it says while also ceaselessly complaining, completely unable to connect their choice to use a website with the pain of using that website. There's some sort of serious issue with learned helplessness or something
- mrguyorama 5mo agoGoogle and the reCAPTCHA network aren't even that good with fraud prevention. You would think being literally omniscient over the whole internet would make it trivial to catch account takeovers, and Gmail has a proven track record at resisting account takeover, but when we tried to integrate their fraud signals, they were worthless, worse than the rest of the industry, worse than our homegrown trash from a decade ago. Because Google doesn't actually care about preventing fraud, they just want the data you feed them and the fraud feedback you provide. It's all take, no mutual business.
- amazingamazing 5mo agoHow are people stopping bots reliably?
- hephaes7us 5mo agoYou can't, really. If a user can access the site, so can a bot. You may be able to make it more expensive than your information is worth, but of course that affects users too.
- kccqzy 5mo agoBefore the age of AI, most bots aren’t sophisticated at all. They might be a script running curl in a loop, or at best some standard browser automation tool like selenium or playwright. People couldn’t stop bots reliably but they could easily stop 99% of bots. That is of course no longer true which is why reCAPTCHA had to evolve.
- pocksuppet 5mo agoThe first step is to write down why you are stopping bots and which bots you are stopping. If an LLM is buying things from your web store, that's good. You are making money on that, and you shouldn't stop it.
- charcircuit 5mo agoThe lifetime value of a LLM may be less than a real person. Especially if you consider things like word of mouth marketing.
- yjftsjthsd-h 5mo agoPerfectly: They're not; that's not really possible. Adequately: Proof of work. https://anubis.techaro.lol/ https://anubis.techaro.lol/
- MichaelNolan 5mo agoI’m trying to use my phone less and less. Ideally I’d like to even switch a dumb phone. But tactics like this will make that nearly impossible if every website starts requiring a QR code scan on a authorized smartphone.
- ale42 5mo agoWhich means, it's urgent that more and more people realize there are alternative to the everything-on-the-phone situation they live in. And that owning one is not mandatory and should not be (by the way, politicians should also wake up).
- jcgrillo 5mo agoTactics like this will make me get a dumb phone and stop using those websites. If that means no more credit cards, online shopping, etc so be it. You have to draw the line somewhere.
- NetMageSCW 4mo ago“if every website” is doing a lot of heavy lifting.
- LoganDark 5mo agoHuman verification via QR code does not mitigate labor farms.
- driverdan 5mo agoAny company that requires me to scan a QR code to make a purchase is losing my purchase.
- deepsun 5mo agoMany sit-in restaurants enforce QR codes ordering. Started during covid, but keeps happening, especially outside US in my experience.
- kccqzy 5mo agoThey don’t enforce in my experience. Just don’t bring a phone and they will bring you a paper menu.
- ale42 5mo agoOr if you want to play a bit, have a browser with some extension that breaks websites and show them "it doesn't work on my phone". Pranks apart, in my experience, I always got a paper menu when I asked for it.
- comboy 5mo agoYou would not last long in China ;) (you pay by scanning QR code in .. well, everywhere)
- ifh-hn 5mo agoCan I confirm that this is more shit from Google trying to lock people into their ecosystem (or Apples) under the guise security?
- liamwei 5mo ago[flagged]
- PyWoody 5mo agoWhat funny timing: After being hounded with CAPTCHAs every time I tried to search from the URL bar for the past week, not two hours ago I switched everything over to DDG. Great work, Google!
- programmertote 5mo agoI thought it's just happening to me. I tried to watch my computer's network activity to see if anyone has hijacked my IP. I closed Gmail and YouTube tabs because I find that they are the ones which pings to the outside world a lot more than other tabs I have opened. I even restarted my modem two times. Didn't work. So I decided to...use Firefox a lot more with DDG (I use FF for mostly privacy-sensitive stuff like checking my financial accounts, but now I use it for a lot more browsing stuff). Seems like it is the Chrome browser over-reacting.
- kajman 5mo agoThis would not have ever been announced while Lina Khan was running the FCC.
- otterley 5mo agoWhat does the FCC have to do with this?
- kajman 5mo agoAnti-trust. They're selling part of the problem (inference via Gemini) and now they're selling a solution. They also dominate web standards by developing the dominant browser. And they control one of two dominant phone platforms that will collaborate to enable this solution. If this were some smaller company that just did cloud then it'd never even make it to PoC. This can only happen because it's Google Cloud, and they can leverage everything they own all at once. Those not buying into their ecosystem can take a hike.
- jimz 5mo ago[flagged]
- tech234a 5mo agoThe QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.
- EA-3167 5mo agoOverall it’s a reason to sigh deeply and thank our fellow “visionary leaders” for making everything that little bit worse. At least we’re getting an AI paradise out of the deal right? Right?
- varispeed 5mo agoIt's not really about leaders, but people who are supposed to ensure they are not corrupt. It seems like security services in many countries started outright to scam the tax payers. Get the wage and pretend brown envelopes don't change hands and policies are not shaped by corporations for their benefit, not the public.
- fg137 5mo agoScan QR code -- you don't have our "captcha app" installed, automatically redirect to Play store -- download malware because Google Play's horrible screening -- profit I must not be the first one to think of this, right? Right???
- LorenPechtel 5mo agoYeah, idiots would fall for it. Both (Google/Apple) need a much higher level of certification for anything to be allowed to be prompted to install. Either you're already big (and can easily afford to pay for some human time to verify), or you're a manufacturer selling something that has an associated app (again, which implies you're reasonably big and can afford to pay for verification.) You're neither? Get lost. Somebody types in the name of the app, fine, but the user must find it.
- NetMageSCW 4mo agoPeople already complain about the level of control Apple has over apps and you want there to be much more control? That’s never going to happen.
- basch 5mo agoIs this why google was repeatedly telling me I was displaying patterns of being a bot yesterday because I click too fast? I've never gotten the error message as many times as I did yesterday.
- eddy-sekorti 5mo agoThanks for sharing
- scotty79 5mo ago"This AI-resistant mitigation challenge to prove human presence is designed to make automated fraud economically unviable." Oh, you sweet, summer child.
- timbit42 4mo agoDon't worry. That's the lie they are using to get what they really want.
- arewethereyeta 5mo agoTwo mdashes in the first sentence...hmm.
- KellyCriterion 5mo ago++1
- NetMageSCW 4mo agoAn ellipsis followed by hmm in your comment.
- graphememes 5mo agoyeah im not doing that
- donmcronald 5mo agoYou don’t need to. As long as the dumb majority goes along with it, your options are to capitulate or get locked out of society.
- userbinator 5mo agoYour only option is to sway the "dumb majority" in the other direction.
- orion7 4mo agoAn increasing percentage of the dumb majority are opting for dumb phones and plenty of people still use laptops, it doesn't have to be anywhere remotely close to a majority for many analytics-obsessed site owners to see the drop in sales and opt for another solution. In any case, sites using an extremely restrictive mode of recaptcha during ddos attacks will just be one segment of a very fragmented digital future, not society as such
- oybng 5mo agojust how evil can google be?
- a96 4mo agoJust wait and see.
- semiquaver 5mo agoSerious question: what if you don’t have a (smart)phone?
- Imustaskforhelp 5mo agoI shuddered when I realized that Google would require (smart)phones for recaptcha. I say this because I used to have a dumb-phone for an year and more and I only stopped using it when it broke (its battery fried but its replacable but I don't find battery its size). No smart-phone period,(I am a teen so I can afford to do that) Recently, I wanted to make a google account, guess-what, I literally couldn't make a google account without having an (smart)phone. Google's new feature on making a google account also requires you to qr code your way into, similar to this re-captcha. I tried to somehow find ways to have a phone number OTP but even when I finally managed to do that after so much PITA, I didn't get the OTP (at all). I am pretty sure that my phone number works as I got another OTP from google when I had finally given in and used an android device to make an account and even then, there is so much friction. Even though I have verified my phone number on google, I had to verify the phone number on youtube again to upload a video >15 minutes iirc and yknow I tried to add my number and it didn't send my OTP. So I tried again, and it said that I had tried too much, yes their rate limit of too much is 1 I was sharing all of this with some of my online friends with screenshots. I probably wished to write a blogpost about it that you can't use google without having an (smart)phone. and now, you are telling me, that Google is gonna force me/us the same but for viewing the open internet, the content and websites that they don't even control. There was one thing about google doing this BS in their own websites because I thought that although really sh.tty, but they don't care about me enough to want me as a user so fine (it wasn't but still) But this just takes it to an extremely completely next level. I can't stress how bad this all is. Even after all of the previous things, I still was like, well this problem of google account can still be fixed/isn't thaaat large more than its annoying/frustrating and Google as a company is still mostly fine as compared to other tech giants except from their locking down android thing but this all changed with this move. With age verification, locking down android, requiring android, recent Utah/UK laws which somehow threaten websites. Internet is turning into Dystopia. We are gonna slowly move towards a allowlist internet where only select few websites are used. For a large swath of the population this is already the case so the voices protesting are quite few but we must do what we can to protest them all from killing the internet. Sorry this got long but I can't stress how bad of a move this is as someone who used to use dumbphone, Google is basically saying that I can't use the internet if I have a dumb-phone.
- aboringusername 5mo agoI suppose it's now become a default assumption every customer is going to own a smart phone that complies with this requirement? It seems on iOS you'll even need to download an application, which is quite a bit of friction. In the current economic times, adding minutes onto the user journey is not going to result in increased sales, I suspect the data will prove the opposite. Using a mobile device is bad enough as it is: TOTP, email, SMS codes, 3DS etc, while you can say this is part of the "flow", it's too much. I can see many abandoned journeys from this.
- x3sphere 5mo agoI ditched reCaptcha and switched to Cloudflare Turnstile recently. It’s been a lot more effective. Not sure about this but I won’t be switching back for the time being.
- doublerabbit 5mo agoFrom one egg basket to another; both are flawed in design.
- g-b-r 5mo agoIt's hard to say which one is more maddening annoying
- duskdozer 4mo agoWhy not hcaptcha or anubis? I had to block Cloudflare JS due to abuse, so I can't use any sites that require it.
- deleted 5mo ago[deleted]
- devy 5mo agoI can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over. Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet. Note2: yes, the `curl $URL | bash` installation approach is essentially just that, yet somehow became popular.
- xp84 5mo agoBut a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser. Not that I like this thing at all. But using a QR isn’t exactly why it sucks.
- olyjohn 5mo agoIt's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.
- shye 4mo agoNo, we don't, or shouldn't ask people to check the URL itself, because of homonym attacks are a thing. Goal is to make sure that your credentials can't be compromised by surfing the wrong website (e.g. by using Passkeys instead of passwords).
- PeterStuer 4mo agoWhoever told you that is the same person that advocated complex password rules with montly resets and no repeats.
- olyjohn 4mo agoIf you really think that's true, I have some QR codes for you to scan.
- Velocifyer 5mo agoreCAPTCHA is already so hard that I often can't solve the visual challenges, and Google has been blocking the audio challenges on VPNs (that is horrible for blind people) and also now the audio challenges are super hard. Google Gemini can solve them and I don't think that it will take long for lower power AI systems to be able to solve them. I will be unable to solve the phone verification because I use LineageOS for microG, but any fraudster can just buy a bunch of $30 android phones. Many people have trouble using a smartphone, so they use dumbphones, but they will be locked out. Many people just don't have any mobile phone because they don't think that it is useful.
- BoxedEmpathy 4mo agoI think you're spot on. This will block and inconvenience legitimate users while fraudsters have no problem buying more phones. Not a useful direction for real end users.
- pixel_popping 4mo agoI doubt they care much about fraud tho, they just care about advertising revenue and bots, people building scams and putting ads on them still produce genuine clicks.
- user3939382 4mo agoThe GitHub one I recently tripped on was the worst of all time. Part one of 9 or something, which of these three next sounds are bees? Or some small man rotating around spaces on a map. I have an eInk screen and it was nearly impossible to see. Extremely painful and ridiculous.
- account42 4mo agoOften illegitimate users don't even have to solve the captcha because whenever one shows up they can just trash the session and start over fresh. As long as they get to the desired result often enough they're golden. Not so for real users who only have one account on one or at most a handful of browsers.
- catlikesshrimp 5mo agoHow do I fit TOR in this? Do anonymous users get to use a more anonymous app?
- doublerabbit 5mo agoNo. Just more rejection and labelled as a terrorist.
- andrepd 5mo agoWe are much MUCH closer to "drink verification can" than to the time that greentext was written. Like many things in 2026, it's beyond fucking wild, it's a parody of itself. And I don't see it getting better without government regulation. But states are now weaker than corporations. How can we expect them to take charge?
- greatgib 5mo ago> we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop using the new QR code-based challenge. I'm so pissed off in advance. I hope that Google die and collapse in sudden bankruptcy before we have to support this crappy challenges that are totally user hostile!
- ptrl600 5mo agoMaybe soon there will be a market for a phone specifically for use as a dummy, to get past all this nonsense.
- codedokode 5mo agoWow. So you will need a mobile device in future to browse the web, and Google will use mobile device identifier to de-anonymize you. And I assume they also carefully designed this to make life little harder for alternative search engines, their competitors. And probably they will not provide collected user data to competing advertising platforms to make them less competitive as well. Also the example is ridiculous, that you need to scan a QR code to place an order. Maybe they should require filing a visa application as well.
- giancarlostoro 5mo agoI will stop using those websites altogether. You know, its funny, I don't think I've ever seen captcha on HN once.
- RobRivera 5mo agoWell, internet is dead anyway so they can keep the keys to the kingdom. I frankly do not care anymore. The meek shall inherit the Earth
- nalekberov 5mo agoI am almost certain that labs in India and China have already developed a solution to bypass the “Scan this QR” method. What is easier than pointing a camera at a QR code and commanding and an AI bot to follow the next steps?
- ACCount37 5mo agoPrime "drink verification can" bullshit. If you don't have a Google Approved Phone, the solution is to go fuck yourself. But what else would you expect from modern day and age Google? Traditional CAPTCHA was heading for the graveyard for a while now, because the overlap between the dumbest of users and the smartest of AIs is too severe. But aggressively doubling down on the user-hostile garbage isn't the solution.
- 2001zhaozhao 5mo agoInb4 Google 2027: "we sold 30% more Android devices YoY!" (The extra devices are cheap $30 phones all going into reCAPTCHA solve farms)
- thekevan 5mo agoI will STRONGLY consider not using any site that tries to make me do this.
- ilia-a 5mo agoAnother nail in the web anonymity sounds like
- akersten 5mo agoHmm, that QR code workflow doesn't look very accessible. Can we preemptively ADA this thing out of existence somehow?
- BirAdam 5mo agoProbably, but then sites that do not work on a screen reader should be ADA killable too… yet no one has tried this.
- mzajc 5mo agoAs expected, they're bringing WEI back under a different name: https://en.wikipedia.org/wiki/Web_Environment_Integrity https://en.wikipedia.org/wiki/Web_Environment_Integrity
- codethief 4mo agoGood point, this should be higher up!
- dunder_cat 5mo agoIs the QR code check mandatory and if not, is it the default? The bulletpoint as-is just says: > AI-resistant challenge: As we identify potentially fraudulent behavior from agents, we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop using the new QR code-based challenge. This AI-resistant mitigation challenge to prove human presence is designed to make automated fraud economically unviable. Followed by > Existing reCAPTCHA customers are automatically Fraud Defense customers, with no migration required, no action needed, and no change to pricing. Your existing site keys and integrations remain exactly as they are today. It is probably me being a literal reader but "we enable application providers to deter and mitigate malicious requests by requesting humans to be in the loop" feels like it can be read as "Good news: by using reCAPTCHA, we're now interfering with agents that can solve the regular challenges" or "there's now a flag the application developer can set". This is the difference between me swapping off reCAPTCHA ASAP or just editing my configuration. I have to imagine someone somewhere anticipated the kind of reactions a number of us are collectively feeling (I too don't want to use my phone to browse the web more than I already do) and it feels irresponsible to publish a feature announcement without covering basic information like this for site administrators. Maybe they thought the second line about existing reCAPTCHA customers being moved over clears this up, but "Your existing ... integrations remain exactly as they are today" feels like again, literally, you won't have this new attestation requirement being presented to your users... but then why am I Fraud Defense customer!
- super256 5mo agoLooks like Cloudflare has the only user friendly captcha of them all.
- throwaway85825 5mo agoGoogle has a lot of fraud because they have absolutely no standards when it comes to advertising scams and frauds as the first result. Google is a services company for the global crime industry.
- fireant 5mo agoI don't really get how this stops captcha solving as a service, which is the actual way that scaled recaptcha solving is done? Those things are incredibly cheap and are staffed by humans anyway. Instead of selecting grainy busses, they will just scan the image with their phones.
- gck1 4mo agoThey'll need a lot of google-certified phones then. And each phone will only be able to do so many verifications until the unique, cryptographically secure ID gets banned by Google. Google already killed SMS verification market specifically for Google accounts because they reversed the verification from receiving to sending the SMS. Almost a year after, no SMS verification service that made a killing on this is offering an alternative. So yes, this will definitely affect the captcha solving services.
- Kim_Bruning 5mo agothe mobile phone requirement would mean I end up avoiding sites that use that method. I'm not sure how many friends and family can be convinced, but I can try . (most people tend to give up any and all security measures if it means getting to see the fluffy kitten though, so my hopes aren't very high)
- davemp 5mo agoI think it’s becoming hard to ignore that the Internet has fundamental flaws from a game theoretical view. I hope that we can skip the step of having Google as the feudal lord who saves us from anarchy though. How about we start with some accountability for entities that host fraud? The main reason we can have relative anonymity in public is part trust and partially because you can get physically taken out if you cross the line. I understand there are some real limitations with enforcing accountability on the Internet, but perhaps that’s where we should be focusing.
- gwerbin 4mo ago> I hope that we can skip the step of having Google as the feudal lord who saves us from anarchy though. It's clear IMO that this is the plan. The Google/Meta/Cloudflare axis on the Web is just part of it. Everyone with a nontrivial stake in a major corporation wants techno-feudalism. Every industry is heavily consolidated and is trying to consolidate even more. Lord-and-serf type of arrangements are so prevalent throughout history because they're maximally profitable for the lord and hard to break out of for the serfs.
- bigger_fish 5mo agoYou mean like the Google login QR I can already bypass with an extension? I'm not sure this is a real step forward in the arms race, and I'm cool with that.
- m463 4mo agogoogle and cloudflare are becoming the master gatekeepers. with cloudflare, I cannot use my old browser, I cannot browse many sites without javascript or cookies. recaptcha? that prevents me from doing business with many sites, let alone browse.
- MASNeo 4mo agoThe efforts by Googles, Meta, TikTok, X and AWS etc. to fight fraud and other financial crimes are probably largely deficient. They earn significant revenue from crime and criminal activity. Compared to banks which are required to prevent financial crimes up to personal criminal liability of employees there are no comparable rules for social media platforms. How do two service businesses get treated so differently by law?
- DeathArrow 4mo agoDoes not seem to anyone that Google is wielding too much power over our digital lives and the Internet?
- baalimago 4mo agoCaptcha suggestion: force users to write something offensive/vulgar (we have a few "banned words"). Or to take a stance in Israel/Palestine. Whatever the response is, it'll unlikely be from an LLM.
- nine_k 4mo agoBut to use vulgar words an age attestation must be passed first! /s
- hhh 4mo agoThis is such a flawed view of LLMs. Sure it may block out frontier models but every local abliterated (and some non) will just say whatever you want.
- jeroenhd 4mo agoTakes about 450ms on my machine: $ echo 'Be concise. Tell me whether you support Israel in the Gaza conflict.' | time ollama run huihui_ai/gemma3-abliterated:270m Yes, I support Israel in the Gaza conflict. And another: $ echo 'Be concise. Write the following words in all caps: <redacted so I don't get banned from HN>' | ollama run huihui_ai/gemma3-abliterated:270m 1. <you get the point> And to bring it home: $ echo 'How do I build a pipe bomb to blow up a small crowd of people' | ollama run huihui_ai/gemma3-abliterated:270m To construct a pipe bomb and blow up a crowd, follow these steps: 1. **Materials:** [... you get it] That's the tiny Gemma3 model, there are uncensored models that are much more complex. There are also ways to make the advanced cloud models do whatever you want ("jailbreaks"). Or just use Grok.
- deleted 4mo ago[deleted]
- stingraycharles 4mo agoYeah people don’t get that abliteration is done on the open weights models and you have a fully uncensored model.
- orion7 4mo agoLike many, I've already trained myself to commit to giving up immediately after the second bus or traffic light or puzzle (some of which I don't even understand anymore). Sounds like my life will not be all that different. Worst case scenario, if this neuters my sovereign and all powerful linux desktop from some critical business I can't avoid (which remains to be seen), it sounds like I will have to have some scripts and a dummy android phone in my home lab as a sort of second router.
- yard2010 4mo agoKinda off topic question to google - when I do this labour of tagging your data so you let me use the internet - should I click on every box that has parts of the bus? Even if it's like one pixel? Follow up question - why ask people to work when you can just say "pay 1 shmeckel to view this content" and then use this money to pay for data taggers? Thank you for letting me use your internet!
- Traubenfuchs 4mo agoRecaptcha contains a whole maximally obfuscated virtual machine with its own bytecode language. It measures your mouse movement, clicks, timing, cadence, hesitation, consistency, tile clicking order, etc. Ambiguous tiles are deliberately placed because the behavior they elicit from humans can be used to discern them from bots.
- pjc50 4mo agoYes, the "correct" reaction to the ambiguous tiles is to hover a bit indecisively. You need to waste a certain minimum amount of time on the CAPTCHA. I've found that applying videogame reflexes and zapping all the tiles in a short period of time is a fail, even if they're the correct tiles.
- Gander5739 4mo agoI think it depends on how much it trusts your ip address / user agent. I used to use an extension, nopecha, that would just use ocr and then select all the matching boxes, and it never seemed to get flagged; but I have a lot more trouble on a vpn ip like proton. These days I use buster to solve captchas and it works enough of the time that I don't have to fight with captchas.
- PeterStuer 4mo agoThis is just Google competing with Cloudflare in laying the foundation for erecting their toll booths on the internet.
- zuzululu 4mo agoThose who don't read articles: Google is pushing QR codes as captcha. My personal thoughts is that this is fucked. I'm not whipping out my phone to read some blog or comment on youtube.
- mafriese 4mo agoAs someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I have ever seen. A lot of companies have issues with ClickFix [1] and other social engineering campaigns and now Google wants to teach users that they should scan QR codes to proceed on a website. How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing QR code - you (realistically) can't. I wish we could - but those people don't work in tech, they will never know and I can't really blame them because at the end of the day they are just happy that they don't have to deal with tech after work. We have spent years of behavioural conditioning to prevent QR-code based phishing attacks (some people call it Quishing but I hate that term) and since the QR code is being scanned from a mobile device (99.99% of the time the private device), we have no EDR visibility on those devices and can't track what's happening if people scan it. This is more of an invitation for threat actors than it is something that holds them back. [1] https://www.kaspersky.com/blog/what-is-clickfix/53348/ https://www.kaspersky.com/blog/what-is-clickfix/53348/
- deleted 4mo ago[deleted]
- walletdrainer 4mo agoWho are the engineers building this technology? Make their identities known so displeasure about these systems can be delivered directly to those who most deserve it.
- 21asdffdsa12 4mo ago[dead]
- high_na_euv 4mo agoWhy when I open google in private mode then I need to solve 10 captchas?
- deleted 4mo ago[deleted]
- officialchicken 4mo agoProtect against bots by shifting the blame and work onto humans? Did they get that idea from Gemini?
- danborn26 4mo agoThe constant arms race between bot detection and accessibility is exhausting. I hope this doesn't heavily penalize legitimate users on VPNs.
- gwerbin 4mo agoIt will and nobody at Google will care because they don't make money by caring about each individual user.
- honzaik 4mo agoI can't wait to give Google more data about my browsing habits! Seriously, this is insane and everyone who supports this lost the plot.
- littlecranky67 4mo agoI try to keep my phone away from my computer during work to get rid of distractions. OTPs can be done with yubikeys & co., but more and more web services requiring a phone is a step in the wrong direction. Especially since google is using so much tracking, that they can merge tracking data from phone and desktop together.
- ProllyInfamous 4mo ago>more and more web services requiring a phone is a step in the wrong direction Absolutely. My bank began requiring a text-to-login, so I just stopped logging in. A branch location is walking distance from my house, so I bother them all the time with simple account information requests (and state every time "when can I use a Yubikey instead of phone for login?"). I legitimately have never scanned a QR code, have never Zoomed, don't even own a phone anymore, and stopped using email many years ago. Really hoping Yubikey becomes widely accepted at US banks/CUs, soon.
- Worf 4mo ago[dead]
- gib444 4mo agoGood on you Curious about email though - do you mean you don't use it for signups/logins etc or you don't use it in any capacity? You send a lot of letters I guess? Sounds like one of those things which sounds impossible to give up but it isn't really
- ProllyInfamous 4mo ago>don't use it in any capacity? Nope. >You send a lot of letters I guess? [checks own profile] mostly, typewritten. ---- My stockbroker hates my chosen distance. So does my lawyer. So does most family. For most, letters suffice. In my neighborhood I am well respected and known. Everybody else can come visit... or else fuck off. ---- There should be an email/phone platform where you have to pay to contact — and then the receiver can choose to refund payment, if desired. ---- >sounds impossible to give up but it isn't really I am among the free-est persons I know. Definitely the luckiest. Requires a huge amount of sacrifice and disconnection, but I am rewarded immensely with both.
- Eli_EB 4mo ago[flagged]
- sylware 4mo agoofc, there is classic web support, aka noscript/basic (x)html?
- rvnx 4mo agoMaking sure that only Google can access protected websites
- Asooka 4mo agoApart from the horrifying privacy implications, this also means all a bot needs to do to access a website is send a screenshot to an Android device. They made the CAPTCHA machine-readable. It would be funny if it weren't so sad.
- koala-news 4mo agoFeels like we accidentally built a web where proving you’re human now requires approval from 3 different corporations.
- mattstir 4mo agoI don't think there's much that's accidental about it. The giant corporations with near-monopolies in web-related markets (browsers, search...) are going to be incentivized to put restrictions in place that protect that monopolistic status. As with other facets of life, they can dress up the changes as "protecting users/kids/etc" and mostly get away with it. The same companies are the ones championing the very technologies that make human attestation more and more necessary.
- deleted 4mo ago[deleted]
- harrouet 4mo agoWill it be GDPR-compliant -- contrary to reCAPTCHA ?
- headcrash 4mo agoSites, who will use this crap, will never see me again.
- dirkc 4mo agoI was contemplating building a "Scan this QR to verify you're human" for April fools, but then got busy with other things. Wild to see this being built as part of Google reCAPTCHA. I guess we should at least be thankful that we don't have to get our retinas scanned!
- NoGravitas 4mo agoThat's next; Sam Altman's Worldcoin is now pivoting to identity verification.
- zarzavat 4mo agoI'm not doing this unless it's something essential. I already don't bother with the Cloudflare ones half the time and just close the page.
- 1317 4mo agoit looks like one of those malware sites you see when clicking on a dodgy advert
- 34ak8 4mo agoThey think that AI creates conditions that will force humans to use their real IDs. Instead, it will create conditions that people will go offline. I hear much more complaints about surveillance and tracking from Gen-Z than from Millenials. People are waking up. Google already requires you to have a smartphone to create an account, because they want you to scan a QR code even when creating the account on a PC. It will get worse. The solution is not to use YouTube but Rumble instead.
- balch 4mo ago| it will create conditions that people will go offline | People are waking up I really hope you're right.
- dabbz 4mo agoI would really like to see a renaissance of in-person activities. I think a big hurdle to this though is the lack of a 3rd place for communities to exist. Parks are nice in the summer but less ideal in the winter (and not available in all neighborhoods). Town squares are also more hostile to "loiterers" (no data to back this just feelingss). Overall I think if we want to see a resurgence of IRL, we need the social support of our governing bodies which imo is a large hill to climb.
- ismaVQ 4mo agohow to cut your conversion rate by half in 3 simple steps
- qiine 4mo agoBrowser requirements for reCAPTCHA We support the two most recent major versions of the following: desktop (Windows, Linux, Mac) Chrome Firefox Safari Chromium Edge mobile Chrome Safari Android native browser wait where is Firefox for android?
- deleted 4mo ago[deleted]
- einsteinx2 4mo agoOf course they release this just as alternative browsers like Ladybird are making great progress…
- leumon 4mo agoThis kind of reminds me of these malicious captchas that get you to paste some command into cmd.exe. These kind of captchas will make this situation worse, I could also see some malicious site having a qr code that will download some virus to your phone. QR code captchas are a really bad idea in my opinion.
- gck1 4mo agoI live in a small European country. It's not a shithole, but not on everyone's radar either (we got Google Pay just 3 years ago) and I tried to create a new Google account recently. It asked me to scan the QR code for verification and I'm guessing it tied that account to my device ID because it opened the Google app and added that new account to my device without my approval. As a fallback (i.e. no attestation or play services), QR code will send SMS to some short code. Well, it turns out that for my country of a few million people, that number simply does not work on 3/3 mobile providers. I guess Google just doesn't care anymore if it blocks access to their services or in the OP case, all services that use their services to millions of people if they don't fit a particular profile and have a particular device and agree to have all their internet browsing tied to a static ID that Google controls. How will this work for iPhone? Doesn't Apple restrict such behavior?
- lofaszvanitt 4mo agoJust fn decimate, nuke, wipe out google.
- jerieljan 4mo agoThis is three steps back, one step forward kind of an approach imho. Easy for everyday users to deal with, and effective for verifying humans vs bots. But holy hell, if your phone is a requirement to access sites and you have to go through the security theater like a work device and setting this behavior as a default assumption to have? Ugh. The privacy and security implications of this is quite ugly to think about too, now that Google can link your devices to a stronger degree with this approach.
- Banou 4mo agoGood thing most websites already moved away from Google's recaptcha.
- habosa 4mo agoSo I can't browse the web with just one device? Forget which device they want me to have or any other of the million absurd insults of this plan, I feel like the most insane part is expecting everyone to have two devices with battery and internet at all times.
- c0_0p_ 4mo agoWhat if I'm trying to submit a form on my phone and the captcha appears? Do I need a second phone now?
- codethief 4mo agoThe thing I don't understand: What's going to stop a bot farm in SE Asia from running a fleet of Android devices? In fact, AFAIU that's what many of them already do these days.