11 ms·
Google Cloud Fraud Defence is just WEI repackaged
- ChrisArchitect 4mo agoRelated: Google Cloud fraud defense, the next evolution of reCAPTCHA https://news.ycombinator.com/item?id=48039362 https://news.ycombinator.com/item?id=48039362
- obaid 4mo ago[flagged]
- jchw 4mo agoExactly my thoughts. I am unfathomably angry and I want to contribute to any effort to dismantle Google as a company.
- pietervdvn 4mo agoYeah, same. It is hard; we start to need a collective boycott. We can all do our part, by using their products as little as possible, contribute to open alternatives (OpenStreetMap, Fediverse, Linux, Nextcloud...) and by stimulating our (non-techie!) friends and family. But it is a lot of work :(
- pessimizer 4mo ago> Yeah, same. It is hard; we start to need a collective boycott. Feelgood slactivism. They don't care about your boycott. They finance their own alternatives because they know what makes you shut up.
- deaux 4mo agoIt's less work than 10 years ago. So many much more mature alternatives.
- buran77 4mo agoThe technical challenge is actually the smaller one. The real one is to get people to care. Don't be tricked by the HN/techie bubble. Most people don't understand the problem, or don't see it as a problem because nothing smacked them in the face yet. Any attempts to explain it makes you sound like a lunatic to some, or just a bit of a worrier to others. Whether it's targeted ads, or training AI on their data, or verifying their age and implicitly identity, or "fraud defense", most people happily take it in exchange for a convenient freebie which is why things keep escalating. It's understandable, people are assaulted with all kinds of abuses from every direction. There are more immediate threats that they can grasp more easily so this stuff has to wait its turn.
- JoshTriplett 4mo ago> Most people don't understand the problem, or don't see it as a problem because nothing smacked them in the face yet. Or don't approach the world with a fundamental mindset of having agency to (help) fix things they see as broken. Just because people see something as bad doesn't mean they inherently see a bright flashing line from that to "so I should do something about it rather than accept it".
- deaux 4mo ago"Technical" isn't really what I meant in the first place. It's about convenience/UX. Lots of OSS has been technically great but very lacking in that part, understandably. The prime recent example of this is gamers. I've seen many people say a version of this: "I tried Linux before but it was too complicated/didn't run most games/when I ran into something I had no idea how to solve it, so I just went straight back to Windows. Now I installed Bazzite cause I was fed up with Win11 and I'm super happy with it. If I do run into a problem I just ask AI and it solves it". I've genuinely seen dozens of comments similar to this. The fact is that there needs to be a very convenient and user-friendly alternative ready to go for the moment that some people do start to care. You need both just as much as each other. And until very recently, those alternatives didn't exist, not at the level of convenience required.
- 7734128 4mo agoIt should not be a "vote with your wallet" situation. It should be governments shattering that organization into appropriately sized companies.
- quantummagic 4mo agoI wouldn't hold your breath. The government is reliant on them for surveillance, censorship, and propaganda. It is a synergistic relationship, not adversarial.
- troupo 4mo agoThese days every time a government as much as thinks of imponging on a supranational corporation's right to do whatever the hell it pleases you'll hear no end of cries ranging from "overregulation" to "tyranny". For an example, see EU's GDPR, DMA etc.
- SilverElfin 4mo agoWe cannot vote with our wallets because there’s no real competition. That’s the problem with the big tech companies and other monopolistic companies in other areas.
- robin_reala 4mo agoIn what area is there no real competition? I can think of real competition in everything Google does with the possible exception of YouTube.
- SilverElfin 4mo agoEverything that gets money from ads. The network effects are too strong for competition against their ads platform and their ability to do targeted advertising based on data only they have. You can’t build a new ads platform and then use that to monetize your company’s other services, because the existing ad networks are so mature and established. Phones. Your choice is Apple or Google. As you said, YouTube. Again, they have users and creators in one place, so it’s hard for a new platform to compete. There are also a lot of enterprise contracts that bundle many things together. Like cloud and their workplace apps (whatever it is now called). But also, just their size is a problem. Look at their AI story. First off, many customers get forced into packages where they get Gemini included as part of the bundle (which means they’re paying for it automatically and have less of a reason to pay for something else). But also - Google was slow to build useful products here. Even though they are late and made many failed attempts like Bard, they can afford to take losses for years that no small company - or maybe even large companies that aren’t mega corps - can absorb. Those other competitors would go out of business and have to be careful and move slowly in spending. But Google’s capital lets them make mistake after mistake but still compete and eventually win. So it’s not a fair competition.
- kogasa240p 4mo agoIMO the biggest issue is that some non-tech people will occasionally be straight up hostile and will whine about not having "features", but then again it only takes a small amount of people taking action inflict real change. Also medium term we need to start making phones (smart OR dumb) that are FOSS as possible. > Linux Open/FreeBSD too, we need to have more redundancy.
- afpx 4mo agoThey're trying to block your ability to boycott. https://en.wikipedia.org/wiki/Anti-BDS_laws https://en.wikipedia.org/wiki/Anti-BDS_laws
- BizarroLand 4mo agoThose are specifically targeted to boycotts of Israel, which ties it to anti-racial discrimination law.
- afpx 4mo agoExactly, didn’t you see who is behind this?
- leoc 4mo agoBut remember: once again, don't simply get angry at Google the institution. Get angry at Page and Brin personally. They have the power to prevent this, a power they were careful to preserve when they gave Google its IPO. They are fully responsible for Google's choices here. But, partly because they aren't constantly jumping up and down drawing attention to themselves on social media, they've tended to escape the same personal scrutiny given to eg. Elon Musk. That needs to end.
- greatgib 4mo agoOn that topic, I would highly recommend you to switch to Kagi! Search is still their workhorse for ad revenue. Less search, less users, in addition to users now just asking chatgpt and co, will hurt them well
- tom1337 4mo agoWouldn’t installing an adblocker basically hurt them as much / more as I still cost them compute but don't get them that sweet ad money?
- JoshTriplett 4mo agoYou think systems that have adblockers installed will keep being able to pass WEI / Google Cloud Fraud Defence checks? This is an attestation scheme. Attestation is about controlling what software you are and aren't allowed to run. If a future version of this allows desktop browsers rather than just phones, it will almost certainly try to do similar forms of attestation, and prevent you from controlling your own software stack.
- SilverElfin 4mo agoThe problem is this type of controlling move, that will be used to benefit their company, is one among many things a company like Google can do that is unethical. They won’t stop. They are too powerful and can get away with it repeatedly. Even if this one thing is stopped, there will always be another dark pattern or another privacy violation or another anti-competitive thing. We really need brand new legislation that makes it much easier to break up companies that are too big, and also to tax mega corporations at a much higher rate than all other companies. Then we can have fair competition and the power of choice. But the existing laws end up with no real consequence for these companies, and even if there’s some slap on the wrist, it takes years in court. New laws must make it very fast and low cost for society to take action.
- revscat 4mo ago[dead]
- walletdrainer 4mo ago[flagged]
- criticalfault 4mo agoone person's villain is another person's hero. I imagine if they would be named and shamed, they would get huge contracts in companies like oracle.
- ipaddr 4mo agoGood luck getting a huge contract with Oracle. Facebook.. yes.
- buran77 4mo agoThe usual argumentation is "I need to make a living" and "if I didn't build it someone else would have done an even worse job, like this at least I could be an activist on the inside and guide the efforts to make it better".
- MSFT_Edging 4mo agoAnother method is to stall and sabotage the development via endless bike shedding, language changes, rewrites, refactors. All normal things in every project. Drag those feet.
- zihotki 4mo agoAnd the people will be just simply fired for underperforming. Or anything else, it's easy when you have at will employment.
- deaux 4mo ago[flagged]
- nerdsniper 4mo agoI think I'd have to be working at Google to afford a family and/or mortgage!
- amazingamazing 4mo agoAI use is far more prevalent now than then sadly. This kind of scheme is inevitable since compute is not free.
- add-sub-mul-div 4mo agoWater use and mass displacement of labor get all the attention but there are so many other more subtle reasons like this that AI is going to be bad for society.
- Flimm 4mo agoI disagree that this kind of scheme is inevitable. We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation. Certainly, Google can choose to avoid it. On the other hand, the AI bubble will inevitably burst, since compute is not free. I look forward to post-bubble AI.
- layer8 4mo ago“Evit” is “avoid” in English, they have the same root.
- sofixa 4mo ago> We can "evit" it through thoughtful discussion, foresight, alternative mitigations, and even regulation Such as? I don't see how regulation would apply here without concrete technical solutions that enforce it. So what alternative mitigations do you have in mind?
- JoshTriplett 4mo agoAmong many other things: Regulate the use of AI to imitate or impersonate human activity. Regulate AI crawling/scraping. Ban scraping entirely, and all models based on it. Regulate maximum model size. These wouldn't eliminate the problem, but they'd change it from "many people do this" to "this is always a malicious attack, react accordingly".
- llbbdd 4mo ago"ChatGPT, generate a blog post that packages an ad for my service that competes with Google by harvesting HN's latent anti-Google rage."
- breakingcups 4mo ago[flagged]
- vrganj 4mo agoThey shouldn't just be ashamed. They should be shunned at the very least. There's a good chance they're on HN FWIW. If you are and you're reading this: Fuck you. Reconsider which side you want to be on!
- faust201 4mo agoSo many in hn already downvoted you. That says the SV nature and opinions in tech sector.
- spankalee 4mo agoGiven all the negative comments here - what is anyone's alternate solution for AI-driven fraudulent activity? CAPTCHAs are increasingly ineffective. Services are either going to go offline or implement some kind of system like this. PII like credit cards or SSNs aren't enough because those are regularly stolen. So where do things go? Fewer services and infinite fraud?
- righthand 4mo agoCaptchas were never effective. It’s an arms race to the bottom.
- nazgulsenpai 4mo agoYes, fewer services and infinite fraud is substantially better to me than the web being controlled by Google even more than it already is.
- frankchn 4mo agoIt will be fewer accessible services for everyone who refuses to use this, that's for sure. In general though, service providers are not going to accept "fewer services and infinite fraud" and thus they will look into implementing this.
- nazgulsenpai 4mo agoI agree in practice money will always win.
- iamnothere 4mo agoThis doesn’t even solve the problem thanks to device farms. There’s not really a solution for this short of aiming a camera at someone’s retina 24/7 plus a fully locked down hardware path. And even that would surely be compromised given enough incentives. People are just going to have to find a new way to monetize. Maybe more things will become paywalled, or sponsored long-term like old TV shows. Again, there’s no good way to solve this, and the “solutions” on offer just contribute to the surveillance state without solving the problem.
- HackerThemAll 4mo agoWe do need to abandon the reality where we use the same few companies on a daily basis and get back to what's now hidden the under-the-surface: forums, blogs, personal websites. We need to re-discover the "free" internet we used to have before Facebook and smartphone dystopia happened.
- Havoc 4mo agoWhether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet
- deleted 4mo ago[deleted]
- ocdtrekkie 4mo ago> rapidly becoming Always has been. Google was creating cartels like the "Open Handset Alliance" literally decades ago. Via their control of Chrome and Search which are both monopolies, Google holds absolute authority on how websites are rendered and if websites can be found.
- parineum 4mo ago> Chrome and Search which are both monopolies I'm on Firefox and use DuckDuckGo.
- ToValueFunfetti 4mo agoYou'd be better off mentioning Safari (17% of users vs. Chrome's 68% and Firefox's 2.2%) and Bing (10% vs Google's 85% and DDG's 1.7%). But nice to know there are two of us!
- newphone733 4mo agoThey lost their search monopoly when LLMs came.
- imglorp 4mo agoLost? No, they shoveled search into the furnace day after day as they prioritized sewage like paid results, link farms, and blog spam while burying the actual result far below, if returned at all. LLM showed up and gave you the direct answer you wanted in <1s; you don't even have to read the shitty troll result page.
- VBprogrammer 4mo agoIn a world where everything is shit, could I at least take away some solace in this helping to reduce Cloudflares hegemony?
- omnifischer 4mo agoNo. They have more in common. I would assume this is an internal joint project.
- biennvops 4mo agoThankfully I haven't met reCAPTCHA that often nowadays, thanks to other providers being more competent. (And no, not you Microslop!)
- spwa4 4mo ago[flagged]
- tadzikpk 4mo ago[flagged]
- iamnothere 4mo ago> Do you seriously think that if Google sees the same hardware identifier 1000s of times a day they are not going to consider that usage to be fraud? Phones are very cheap, especially refurbished phones. Just have the phones mimic real life sleep/wake cycles and take occasional breaks. Use 25% more devices to account for the loss in uptime. Besides, some people (often unemployed or disabled, and possibly with sleep disorders or mania) actually don’t do anything other than scroll on their phone all day and night. So you can’t rely on this as a good signal without creating even more blowback. And you really don’t want too much blowback from troubled people who have infinite free time.
- varenc 4mo agoThis still doesn't seem very economical for the bot farm. For a device to look legit it has to only use its hardware identifier about as often as a real human would. This massively changes the economics. If you have 1 bot farm customer that wants 20,000 solves in a day, the bot farm would need something like 20000/200=100 phones to provide this. (assuming a real user can do about 200 solves before being flagged). And the cost for the bot farm being detected is very high because if a phone's root key loses trust it destroys the value of the ~$30 phone they purchased. And of course, I'm sure Google can use the phone's value as another signal for trustworthiness, treating cheaper phones many generations behind as less trusted. I don't think bot farms will go away completely, but the price will spike massively, which is all you need to discourage many types of abuse. Some Googling show that reCAPTCHA solves are about $0.003 each right now, so quite cheap. With this new reCAPTCHA, I suspect the price will jump massively.
- Velocifyer 4mo agoI'm pretty sure that the Ai copied the $30 number from my hacker news comments. However in the USA it is true. https://www.walmart.com/ip/Straight-Talk-Motorola-Moto-g-2025-5G-64GB-Blue-Prepaid-Smartphone-Locked-to-Straight-Talk/14552506783 https://www.walmart.com/ip/Straight-Talk-Motorola-Moto-g-202... (carrier locks don't matter for this usecase.) I am not sure that that storing unique device identifiers is legal in the EU.
- munchler 4mo agoI think this is the third HN link I've clicked on in a row that leads to an LLM-generated article. I'm not opposed to AI, but I'm tired of seeing it quietly substituted for human thought and expression.
- alex_duf 4mo agoI'm seeing this stance a lot "this is obviously AI generated" Why? What's LLM generated? How can you tell? To me what's obvious is that our trust system is already breaking down. Commenters accusing each other of being AIs is also another example of this.
- bakugo 4mo agoThe entire article is just one long stream of short, punchy, declarative sentences. The latest Claude models are notorious for writing like this. There's also a few cookie-cutter patterns that should immediately jump out at you if you're at all familiar with AI writing, such as: > No hardware identifier is transmitted. No attestation is required. No certification layer determines who may participate. User privacy is structurally preserved, not promised. > Google Cloud Fraud Defense is not a reCAPTCHA update. The QR code is the visible mechanism, but device attestation is the real product.
- munchler 4mo agoThe choppy language is the biggest trigger for me. Examples: * "With Fraud Defense, there was no process to respond to. The product launched. The requirements page went live." * "That is not a technical limitation waiting to be engineered around. It is the mechanism." * "The defeat is mechanical. Bot operators point a camera at a screen, a trivial automation with off-the-shelf hardware." I could be wrong, of course. Maybe humans are starting to write like LLM's, or maybe it's just confirmation bias on my part.
- gruez 4mo ago>Why? What's LLM generated? How can you tell? Not the guy you're responding to, but: 1. The high number of (em) dashes is suspect, though it's unclear whether they manually replaced the em dashes or is actually human generated. 2. "One additional failure worth noting: one incident response professional in the HN thread, raised a concern that operates independently of the bot problem" feels out of place for a content marketing piece. HN isn't popular enough to be invoked as a source, and referencing it as "the HN thread" seems even weirder, as if the author prompted "write a piece about how google cloud defense sucks, here are some sources: ..." 3. This passage is also suspect because it follows the chained negation pattern, though it's n=1 >No hardware identifier is transmitted. No attestation is required. No certification layer determines who may participate. edit: I also noticed there are 2 other comments that are flagged/dead expressing their reasons.
- dgrin91 4mo agoMaybe a dumb question, but how is this suppose to work for iphone users? They wont have google play, and it seems like android/google play is required here? There is no way they would cut out such a huge chunk of the market.
- gruez 4mo agoiPhones have attestation too: https://developer.apple.com/documentation/devicecheck/establishing-your-app-s-integrity https://developer.apple.com/documentation/devicecheck/establ... It'll just be more clunky because you have to install their app.
- pat2man 4mo agoThey also have Private Access Tokens: https://developer.apple.com/news/?id=huqjyh7k https://developer.apple.com/news/?id=huqjyh7k
- jeroenhd 4mo agoI believe the latest versions of iOS just work from the browser, you only need to install the app for older versions of the OS. I don't know what technology they're using, but when I scanned the QR code it launched (downloaded?) an iOS app of sorts with one tap, similar to the way Google tried Instant Apps a few years back. Didn't even need to double tap the power button like usual.
- thecatapps 4mo agoApp Clips -- very underutilized but also very cool. https://developer.apple.com/documentation/appclip https://developer.apple.com/documentation/appclip
- JoshTriplett 4mo agoThe claim is that an iPad/iPhone will also work. Not that that makes it acceptable; if anything, it's worse, because if it were Google Play only it'd be more obvious how unacceptable it is, whereas catering to the duopoly makes it less obvious how much it excludes people and builds a reliance on proprietary systems.
- SwellJoe 4mo agoFrom "Don't be evil" to building the largest, most invasive, surveillance operation the world has ever seen. That was true before this, but this indicates nothing will ever be enough. Google will always want to track more of everyone's activity online, and will use every tool at their disposal to do it.
- curiousgal 4mo ago> Google It's not Google, it's someone. A person came up with this idea and is pushing it through. We should stop treating corporations as some abstract entity instead of a group of sick people making these kinds of decisions.
- lambdaone 4mo agoThis is truly disturbing, and trying to sneak it in like this without public discussion is disingenous. Hopefully it will be shot down like last time - at the very least, there are surely antitrust issues here.
- phpnode 4mo agoLast time they tried this they laundered it though an employee's personal github to distance it from google itself, then framed the proposal in the most disingenuous manner possible, as if it was something that users wanted rather than another mechanism for google to exercise control
- nerdsniper 4mo agoI agree on the antitrust issues, but I’m not convinced that’s seen as a serious barrier these days.
- gruez 4mo agoAs much as I hate whatever google's doing, this article has some issues: >For operations that need Play Integrity attestation specifically, a compliant Android device costs approximately $30 at current market prices This assumes the logic on google's side is something like `if(attestationResult == "success") allow()`, but it's not hard to imagine the device type being factored into some sort of fraud score. For instance, expensive devices might have a lower fraud score than cheaper devices, to deter buying a bunch of cheap devices. They might also analyze the device mix for a given site, so if thousands of Chinese phones suddenly start signing up for Anne's Muffin Shop, those will get a higher fraud score. >Firefox for Android does not appear in Google’s stated browser support list for Fraud Defense. The browser only needs to show a QR code, so if you're on firefox mobile they'll either open a deeplink to google play services on the phone itself, or show a qr code. >One human solving a single challenge pays a negligible cost. A bot farm running concurrent sessions faces exponential compute costs with each additional attempt - and AI agents, which consume GPU cycles to operate, face identical penalties regardless of how sophisticated their reasoning is. PoW for bot protection basically never caught on because javascript performance is poor, and human time is worth more than a computer's time. An attacker doesn't care if some server has to wait 10s to solve a PoW challenge, but a human would. An 8-core server costs 10 cents per hour on hetzner. Even if you assume everyone has a 8-core desktop-class CPU at their disposal (ie. no mobile devices), a 6 minute challenge would cost an attacker a penny. On the other hand how much do you think the average person values 6 minutes of their time?
- sylware 4mo agoI keep banning gogol Ipv4 ranges because of scanners, script kiddies (and maybe worse). Yes, I am self-hosted, and without paying the DNS mob.
- everdrive 4mo agoNo one should ever browse the web on a smart phone. Not joking.
- llbbdd 4mo agoPhone is small computer
- mindslight 4mo agoNo one should ever browse the web from an ESP32 either. Like seriously the dark patterns are bad enough from a desktop where you've actually got the screen real estate to see the whole page, have other sites open for comparison, have a keyboard to type your own notes, etc. Most browsing can simply wait, especially the adversarial-commercial type we're talking about here.
- tremon 4mo agoIt is, just like a calculator is a small computer. It's not a personal computing device though, in the sense that the user can't develop and deploy their own software/tools on it.
- llbbdd 4mo agoEven if that were true, that has nothing to do with browsing the web on it
- everdrive 4mo agoSure, and the north korean Linux distro also runs on a computer. I still wouldn't touch it.
- llbbdd 4mo agoIs it just a matter of not trusting the OS? I'm trying to figure out why "smart phone" is the discriminator here.
- cynicalsecurity 4mo agoThis is security theatre. This isn't going to help against bots in any way.
- opengrass 4mo agoFor merchants who don't want geeks as customers, cool As a web-wide captcha replacement, not cool
- DonThomasitos 4mo agoWe see the fundamental forces of capitalism at work: To justify valuation, Google needs to grow. When they feel a ceiling, they broaden their search to anything legal that makes customers pay - even if it contradicts their longterm interests. This created countless attack angles for startups. The good news: we already have a solution! Monopoly laws. In case of the internet, no company should be able to have this much power. The bad news: US decided to weaponize big tech’s leverage over the world and does not enforce these laws anymore that fix vanilla capitalism.
- Gagarin1917 4mo ago>We see the fundamental forces of capitalism at work: To justify valuation, Google needs to grow. You’re confusing markets with capitalism. Market Socialism (the only reasonable kind) would have these same issues. If Google was owned by the workers instead of capitalists, it would still have incentive to grow. The worker owners would have the exact same incentives as current owners. The only difference would be who the owners are. Capitalism is not actually “the final boss” that internet leftists make it out to be. Socialism is not the panacea that leftists make it out to be. Surveillance is not a “capitalist only” thing.
- DonThomasitos 4mo agoI agree, thanks for clarification. I did not want to argue in favor of Socialism - my criticism here is that „free market correction instruments“ like antitrust, monopoly etc are absent.
- jensenbox 4mo ago[dead]
- AlienRobot 4mo agoI think the idea is good if it could actually curb bot traffic that currently plagues the Internet. However, a lot of recent bot traffic are sophisticated scrappers called "LLM's." You can tell claude to "research X from this www.example.com" and will automatically scrape it and summarize it, something that a LLM is perfect for. Gemini tends to share links instead, presumably because most of Google's revenue comes from ads served on those websites, so if it completely killed the traffic to those websites it would just make less money. Incidentally, I wonder if Claude/Gemini use an search engine-like "index" of all websites or it refuses to cache anything to always fetch "fresh" data. If this is employed, I don't think the web is only going to be gatekept to Google devices. I think it will also be gatekept to Google's AI's. Google would be able to display a captcha that no LLM could defeat, and then just let its own LLM pass through. The same could be said about its other bots, such as the web crawler. Google's bot could crawl webpages that no other crawler would ever be able to simply because it has free pass to captcha-gated GETs. Although the same could be true already today.
- jeroenhd 4mo agoTheir product page is full of info about how this works with "agentic" cruft. They're still permitting your regular old scrapers and bots for as long as they like you. Hope you're not thinking of running an independent system instead of a large cloud platform!
- stronglikedan 4mo agoWhy should I even care anymore? I no longer need to access random websites to find information since I can just ask the AIs.
- a2128 4mo agoAre you genuinely asking? To pay your taxes, order items online, access your bank account, log into your favorite AI service, there are very often CAPTCHAs involved. Try going a month with CAPTCHAs blocked in uBlock Origin, and you will find yourself unable to do many basic things.
- fg137 4mo agoNot saying this is any better, but IRS partnered with id.me to enforce ID + face recognition before you can log in to view your records. We are truly doomed.
- AntonyGarand 4mo agoWhere do you think the AI gets this information? They also need to browse the web, and are more likely to be blocked by these measures than humans
- raincole 4mo ago> are more likely to be blocked by these measures than humans In other words these measures work as intended...?
- garciansmith 4mo agoEven besides services you might need to access, as pointed out in another response (e.g., banks, shops), how are you going to check the veracity and understand the context of the information you seek without going to the (possibly hallucinated!) sources? But I guess a lot of people who are into using AI like that just don't care.
- deleted 4mo ago[deleted]
- throwaway27448 4mo agoFor those who don't know: WEI is a boy band known for singles such as "Twilight"[0]. [0]: https://youtu.be/4BYkuPUQoWE https://youtu.be/4BYkuPUQoWE
- jeroenhd 4mo agoI saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either. Now we have tons of fingerprinting and behaviour analysis but governments are cracking down on that. Plus, YouTube had a massive ad fraud problem with ads being played back in the background in embedded videos, so their detection clearly wasn't good enough. There aren't many good ways to prove you're not a bot and there are even fewer that don't involve things like ID verification. Their opt-in approach helps shift the blame to individual web stores for a while, so who knows if this will take off. But either way, in the long term, the open, human internet is either going away or getting locked behind proofs of attestation like this. Apple built remote attestation into Safari years ago together with Cloudflare and Google is now going one step further, as Apple's approach doesn't work well against bots that can drive browsers rather than scripted automation tools. Luckily, their current approach can be worked around because it's only targeting things like stores now and you can buy things from other stores. Once stores find out that click farms have hundreds of phones just tapping at remotely served content, uptake will probably be limited. It'll be a few years before this is everywhere, but unless AI suddenly isn't widely available anymore, it's going to be inevitable.
- dakolli 4mo agoI personally think its easier to detect llm controlled browser sessions, the people deploying them are far more naive and inexperienced than traditional scrapers/crawlers. insert You wouldn't bring a 40 Petabyte Zip Bomb to School, would you? meme
- jeroenhd 4mo agoPart of the problem is also that Google wants to permit crawlers to do some things but jot others. Their announcement is full of buzzwords about "agentic" things. Detecting LLMs is one thing, but imagine the power of being able to pick which LLM browsers are permitted and which aren't! I think Google is being too early to the party with this. Cloudflare still has CAPTCHAs to throw at the wall. There are ways other than attestation to verify that someone is a real human, but they're getting more and more annoying to real users and harder and harder to implement on a small website. Despite the massive implications, this is a simple system that just works for the 99% of people who use Chrome or Safari or at least have access to an Android phone or iPhone somewhere. It's quick, doesn't require installing apps or creating accounts, and it just works from both the website perspective and the user perspective. Of course when you start thinking about people with disabilities things become problematic, but when have tech companies ever really cared about that sort of thing? Inclusiveness was fun and all for a while, but the clowns the American people elected banned that sort of thing for any company considering government contracts, and big tech licked that boot like it was made of honey. The world becomes a lot easier if you just decide to ignore all edge cases and assume customers who disagree with you didn't matter anyway. And infuriating as it may be, for companies like Google, that business model works.
- motbus3 4mo agoI strongly suggest people move away from chrome. They lost all sense of respect. I know it is a small move, but as it happened when chrome started, this opens opportunities for other players
- hbn 4mo agoI really tried to switch off Chrome when they broke ad blockers, I gave it a good few months trying out alternatives but I really don't like any of the other browsers. I do primarily use Safari on my Mac, but on Windows where I don't have that option, I don't like any of the big players, and I don't really trust the smaller players. Even the "big" smaller players are not that trustworthy when it comes to security, like Arc browser's "Boosts" feature that enabled remote code execution. So now I'm back on Chrome.
- NegativeLatency 4mo agoVery funny that if you want to start a bot farm you also go and buy a bunch of random android devices.
- Ritewut 4mo agoI do wonder how people who work on this don't see themselves as the bad guy.
- BizarroLand 4mo agoThey have blinders on made out of money.
- yard2010 4mo agoSpecial snowflakes kind of people, it takes one to know one.
- 0______0 4mo ago$$$
- rodchalski 4mo ago[flagged]
- deleted 4mo ago[deleted]
- janalsncm 4mo agoI think I understand why Google wants to do this, and I think I understand why people are opposed to this particular solution. It’s also worth noting that the author of this article is selling a proof of work solution to the problem. I am fairly skeptical that proof of work is the right way to go here. A lot of users of the web are using older hardware. Adding a computational toll booth doesn't solve the problem in a world where people have differing amounts of compute to spend. On the other hand, a botnet might have access to thousands of computers and may not actually care about waiting an extra 10 seconds. Or worse, they will come up with a custom solution on an ASIC that solves your proof of work puzzle thousands of times faster than grandma‘s laptop.
- mafriese 4mo agoI posted a comment on the announcement when it was posted here: >As someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I have ever seen. A lot of companies have issues with ClickFix [1] and other social engineering campaigns and now Google wants to teach users that they should scan QR codes to proceed on a website. >How should we realistically teach Susan from HR the difference between a real Google Captcha QR code and a malicious phishing QR code - you (realistically) can't. I wish we could - but those people don't work in tech, they will never know and I can't really blame them because at the end of the day they are just happy that they don't have to deal with tech after work. >We have spent years of behavioural conditioning to prevent QR-code based phishing attacks (some people call it Quishing but I hate that term) and since the QR code is being scanned from a mobile device (99.99% of the time the private device), we have no EDR visibility on those devices and can't track what's happening if people scan it. >This is more of an invitation for threat actors than it is something that holds them back. [1] https://www.kaspersky.com/blog/what-is-clickfix/53348/ https://www.kaspersky.com/blog/what-is-clickfix/53348/
- doug_durham 4mo agoThis seems to be an advertisement for Private Captcha. I don't know a lot about the service, but it seems inherently ablest. Does proof of work, support blind users? Does it is support special needs users with cognitive impairments? The QR code and photo support a wide variety of users. What not support a variety of methods. Why does it need to be one or the other?
- kmeisthax 4mo ago> The defeat is mechanical. Bot operators point a camera at a screen, a trivial automation with off-the-shelf hardware. For operations that need Play Integrity attestation specifically, a compliant Android device costs approximately $30 ($29.88 in Wallmart to be precise) - for a professional bot farm, which purchases devices in bulk, this is the fixed cost without material disruption to operations. That's $30 per account, not one time. Because of the following: > Device attestation does not just gate access - it produces attribution. A device with a stable hardware identity creates a persistent identifier that crosses sessions, browsers, and private browsing modes. If you put all your bot accounts on one device, they all get banned at once. So fraudsters have to spread their accounts across multiple devices and replace them when they inevitably get banned. That's the reason for all the spying, attestation, and lockdown bullshit behind Google Cloud Fraud Defense. It is far easier to ban fraudsters if you just let the Maoists run the Risk Department. The author proposes an alternative solution: proof-of-work. And, yes, there are use cases for that, such as Anubis. Google might even want to consider a proof-of-work option in certain scenarios. But there is no scenario in which someone's phone deliberately burns $30 worth of compute - perhaps a quarter of the user's battery - and the user still has a good onboarding experience. Most of your actual users are not going to be able to burn compute as efficiently as fraudsters, either - so maybe you have to burn the whole battery on a phone to cost a fraudster $30. Proof-of-work is, strictly speaking, anti-egalitarian and anti-democratic. "One CPU, One Vote" is less useful than you think when you realize fraudsters have the money to just buy lots of CPUs to always win[0]. Every Risk Department eventually reinvents arbitrary and capricious punishment. When you have no legal authority to prosecute crime, you rely entirely upon your freedom of association and ban people with a hair trigger. It's the only thing that works. Personally, I'd rather live in the world where governments actually took fraud seriously and corporations didn't have to do this, but for right now, GCFD is at least less onerous than WEI in the sense that WEI was going to lock down all browsers. GCFD just means I have to keep a Google-approved phone around to scan a QR code every once in a while. [0] I'm not mentioning the massive waste problem proof-of-work creates, because obviously attestation will also produce waste. Actually, if anything, the fraudsters will probably wind up dumping all their banned devices on the used market and ruin it.
- prima-facie 4mo agoWhat Google has done is incredibly clunky and only serves its own interests. We already have methods to prove that we're human. 1. lots of laptops have fingerprint readers & TPM2 build-in 2. lots of folks own Yubikeys or FIDO2 keys - if these became the norm then the price would come down significantly. Both of these methods only require a tap to authenticate to a website. Both provide public-key authentication, and both provide some level of proof of work / require human interaction, without revealing the identity of the end-user. Why not use or standardise these? because there's no benefit to Google of course.
- karlgkk 4mo agoneither 1 nor 2 can prove you're a human. sorry
- nerdsniper 4mo agoThose don't prove that a human is present. A FIDO2 key can be automated by electronic relay. The only way to do this involves device attestation - locking devices down and utilizing hardcoded TPM/Secure Enclave esque chips. The best we can hope for would be an open standard for those chips so that people can use them with their own X.509 certificates that lets them choose their own CA.
- nitwit005 4mo agoReal hardware doesn't mean a human is present either, unfortunately. It just means that you have to spend on real devices to bypass these defences.
- kalabrium 4mo ago[dead]
- tinfoilhatter 4mo agoConsidering Google's origins and early backers, this shouldn't come as much of a shock to anyone: https://qz.com/1145669/googles-true-origin-partly-lies-in-cia-and-nsa-research-grants-for-mass-surveillance https://qz.com/1145669/googles-true-origin-partly-lies-in-ci... The military industrial complex created the internet, and has funded many of the big players in Silicon Valley. Their goal was never an open and free internet.
- btown 4mo agoDo we know if this is immediately going to slot in wherever reCAPTCHA is currently used / is there a rollout plan? Or will site operators manually opt into the new system? Is there even a way to opt out? I can think of many sites where, for users that trigger captchas often, introducing a multi-device workflow is even worse for those users than clicking traffic light images. An automatic rollout would be hostile to those operators!
- 23062192 4mo agoHello
- Velocifyer 4mo agoAlso, Google sometimes blocks the audio captchas (messing up blind people) and they are nearly impossible right now.