cross-posted from: https://lemmy.ml/post/47972724

i encountered this for the first time today while attempting to read something on archive.today.

i confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.

the old type of captcha remains available too, for now:

screenshot of text: Important: Mobile verification for Google Cloud Fraud Defense is an experimental challenge type in Preview. Visual and audio challenges are available as alternatives for users who can't complete mobile verification. To use them, click the Visual  or Audio  buttons.

  • Snot Flickerman@lemmy.blahaj.zone
    Aquileo | link
    Aquileo | fedilink
    English
    Aquileo | arrow-up
    220
    ·
    2 months ago
    1. People without a mobile device are fucked out of being able to pass a captcha

    2. As if this isn’t a way for them to associate multiple sessions on multiple specific devices with one another, this is just another avenue for data collection, period. Hidden under the guise of “more secure.”

    • Prove_your_argument@piefed.social
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      50
      ·
      2 months ago

      Captcha has been one of the greatest google acquisitions ever.

      They acquired it under the guise of improving OCR and have since morphed it into an AI data farm (how else is google lens gonna know what objects are what?) and now total insight into a users every single action from desktop to mobile, tying it all together into a surveillance nightmare.

      I can guess the permissions that the recaptcha app needs now. Probably something akin to root access with all datapoints and considerations you could think of.

      • No1@aussie.zone
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        20
        ·
        2 months ago

        I used to always add one incorrect tile and skip one correct tile.(It would still pass)

        I thiught I was such a rebel lol

        Then I figured, they’d be stupid if they didn’t show the same image to multiple people…

        • Prove_your_argument@piefed.social
          Aquileo | link
          Aquileo | fedilink
          English
          Aquileo | arrow-up
          3
          ·
          2 months ago

          I’ve had many, many not traffic light and motorcycle/bicycle recaptchas. They’re probably leaning a bit into self driving learning the past few years.

          Lens has a lot more data points nowadays after everyone’s google photos was used for training for what, 10+ years at this point?

          Google harvested all human typed words 15 years ago with the google library project. They’ve been hoarding and processing data for models forever.

          • Lumidaub@feddit.org
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            1
            ·
            2 months ago

            I was being at least partly facetious because I rarely get anything but motorcycles and traffic lights and even then it’ll most likely ask me about buses or bridges. Not disagreeing that they’re hoarding data :)

      • MrKoyun@lemmy.world
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        3
        ·
        2 months ago

        The point with captchas is not really that bots can’t pass them, more that its too expensive to pass them consistently with a hurtfully large enough volume of bots.

        • HeHoXa@lemmy.zip
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          2
          ·
          Aquileo | edit-2
          2 months ago

          I’d heard of this strategy, like making it perform some kind of costly encryption that’s irrelevant to a human user but restrictively expensive for a bot army.

          But does decoding a QR code apply? I never really thought about it. I guess it’s an image, it’s at least a little big by comparison… but it’s also in a restricted, easy to capture spot and maybe could be minimized to a fairly small pixel set? Idk how many key pixels you need to parse a QR code… I guess I could Google

          *typo bit --> bot and bit --> big… I’m full of bit

          • MrKoyun@lemmy.world
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            2
            ·
            2 months ago

            I don’t know much about this new captcha system, but I feel like the challenge wouldn’t really be in the scanning of the qr code itself but more so on making the device you’re scanning with seem legitimate. They could check usage patterns, what apps are installed, how many accounts are added and are they actively used, location and sensor data, are the hardware specifications really unusual, are they constantly trying to complete random captchas… Stuff like that to tell apart a real user’s device from a bot or sandbox. The QR Code is probably just a random ID for which captcha instance the user is trying to pass.

            Also I just realised this but this is probably inconvenient as hell. Like I do NOT want to constantly be picking up my phone to scan QR codes when I’m trying to go around the Internet. What if my phone is on the other side of the house? I don’t want to get up and walk all the way over there! If this gets fully rolled out there may actually be a small dip on the amount of desktop users of websites because they just leave when they are hit wth this captcha instead of bothering to scan a code.

            • HeHoXa@lemmy.zip
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              1
              ·
              2 months ago

              Heard. We have a QR 2auth system for one of my work domains, and I let out an exasperated sigh every time I realize I have to get my phone out

    • adarza
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      14
      ·
      2 months ago

      i have one. but it isn’t android, or ios, or ‘smart’ in any way. it doesn’t even text. it’s just a telephone that fits in my pocket and connects to the cellular networks. it’s all i want. it’s all i use. it’s all i’ve needed ever since i got my first one about 25 years ago.

    • MrKoyun@lemmy.world
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      9
      ·
      2 months ago

      It really should be illegal to build systems that require a user’s access to any unrelated technology. You shouldn’t be forced to have a phone to pay a parking fee or to get on the bus. You shouldn’t need an app to charge your car. You shouldn’t need to use proprietary software from one spesific company to pass a captcha on a random site.

    • Prove_your_argument@piefed.social
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      42
      Aquileo | arrow-down
      1
      ·
      2 months ago

      Sorry, my faith in users is basically zero. These dummies will go to websites that tell them to copy code and run it with win+r. They’re morons and will do anything if a website promises them something.

        • Prove_your_argument@piefed.social
          Aquileo | link
          Aquileo | fedilink
          English
          Aquileo | arrow-up
          2
          ·
          Aquileo | edit-2
          2 months ago

          At work? Crowdstrike is kind of the training wheels for people who don’t want to use application whitelisting or group policy that disables users running various terminals.

          Training isn’t the answer, because training is basically an industry propped up by knowbe4 from convincing cybersecurity insurance that it’s the right thing. We do training where I work and everyone falls for the same old shit, raise information, pay information, promotion information and performance review content. Doesn’t matter how many indicators of compromise are hidden in the message, but they’ll gladly just keep clicking along or running code that is prompted because the desire sensor overrides the training.

          Anywho, nowadays not giving users admin rights is simply not enough. The script creating people often know how to use privilege escalation exploits without issue to gain control even when a user can’t. Really need a tool that can detect behavior and block it, or lock the system down somehow.

    • IratePirate@feddit.org
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      15
      ·
      2 months ago

      Just like Recaptchas haven’t been a challenge to bots for a long time. Still, we had to deal with this shit. Makes you wonder if it’s just a stupid fucking pretext… 🤔

          • 520@lemmy.zip
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            8
            ·
            2 months ago

            Something like that. Emulators also give the ability to emulate cameras using pictures or video feeds.

            They just need to set up a Google play equipped emulator, set the picture as simulated camera input and put in the inputs to the emulator (also automatable)

          • boonhet@sopuli.xyz
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            4
            ·
            2 months ago

            May have to stream a video of the screen into a scanner app, but shouldn’t be difficult anyway.

            One of the forms of digital ID in use in my country now has a new way to use it, which the government websites use now. You always needed a mobile device for this one anyway (phone holds the private keys and you have to enter the PIN 1 or PIN 2 depending on whether you’re authenticating or authorizing something), but it used to be that you could enter your ID code and get prompted for the PIN (with a verification number to make sure you’re responding to the prompt you think you’re responding to), now it’s either on-device from the default browser to the app, OR on desktop you have to scan a QR code that’s a moving target, it changes a couple of times a second so you couldn’t send a screenshot to someone else to scan. This is meant to prevent scams where someone gets you to just enter your PIN over a phone call.

            I don’t know if the google thing is similar though or if it’s a static QR there.

      • Renat@szmer.info
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        2
        Aquileo | arrow-down
        1
        ·
        2 months ago

        My cat once jumped on keybard and wrote “ghfhghgghhfjgfhf” on Discord chat. The first non-human with acces to computer.

    • lemmylump@lemmy.world
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      9
      Aquileo | arrow-down
      1
      ·
      2 months ago

      I once made QR code stickers that placed people on a website warning them to stop trusting QR codes.

      I spent a year traveling and everywhere I saw a QR code my sticker QR code went over it.

      You target the right locations and spoof the website and you can get credit card, phone, email, address. Svan this QR code for 20% off blah blah blah.

      Do use them.

      • Buckshot@programming.dev
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        3
        ·
        2 months ago

        Noticed parking meters here have prominent labels now stating they do not use QR codes. I’m sure that’s just providing the spot to put the scam QR code, but it’s better than nothing.

  • tjoa@feddit.org
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    57
    ·
    2 months ago

    I know it has been said already but how stupid is it to teach users the pattern of randomly scanning QR codes. So ironic given that reCaptcha is for security in some sense.

      • SolarMonkey@slrpnk.net
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        14
        ·
        2 months ago

        I had a site I was gunna buy stuff from ask me for a video selfie to “prove” I was over 21.

        First if all, I wasn’t buying anything controlled, so thats ridiculous over-reach, and second of all LOL FUCK NO I’m not giving you, some random-ass e-commerce site, my fucking biometric data. That’s absolutely insane.

        Needless to say, I blocked that site on my pihole, so it no longer exists to me as an option. Sent them a message letting them know they lost a rather substantial sale from that shit. I’ll do that for absolutely every one, same with ID or whatever else. I could just use the tricks kids use, but that still rewards them for this bullshit with money.

        I’ll just stop using the internet if it becomes a thing everywhere. It’s not really worth being on anymore, for the most part, anyway.

        • freedickpics@lemmy.ml
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          4
          ·
          2 months ago

          I don’t blame you. Personally I get more satisfaction from using fake IDs or directing a video selfie thing to a video game character etc or finding some obscure bypass to whatever bullshit they throw at me. That way I still get what I want from the website and they get nothing of value from me, lmao.

  • antonim@lemmy.world
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    53
    ·
    2 months ago
    1. Hype up AI.

    2. Everyone starts scraping the internet to obtain training data for their AI.

    3. To block the scrapers, countless sites implement stricter bot detection tools.

    4. The owners of the bot detection tools now effectively hold all of the internet by its throat, deciding who can access what and extorting more and more data from you to verify you’re human.

    Fucking genius.

    • Scrollone@feddit.it
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      9
      ·
      2 months ago

      It’s already happening. They tell you to scan a QR code that links to a website where they ask you to log in with your Google account (but it’s just a phishing page).

      Good job Google!

  • Hemingways_Shotgun
    Aquileo | link
    Aquileo | fedilink
    English
    Aquileo | arrow-up
    41
    ·
    2 months ago

    Any website that chooses to use this service will simply not get my traffic. If enough people feel the same, those websites will lose clicks and eventually tell Google to pound sand.

    Imagine the utter hubris on these fuckers to think that people will get a google device just to access a website.

    Or to think that an average user sitting at home would run to another room to grab their phone so they can verify themselves on the desktop just to visit blackcougar.com

    • DFX4509B@lemmy.wtf
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      21
      Aquileo | arrow-down
      2
      ·
      Aquileo | edit-2
      2 months ago

      They’re using the fact that everyone else both already owns a Google or iOS device, and does everything on those devices, to punish desktop and alt mobile OS users.

      The fact that this is going on right as AluminumOS is down the pipes, and right as rigged parts prices threaten to kill desktops as an option to begin with makes this especially sus.

      The way things are going right now, I won’t be surprised if we see a computing future where you’re either on a Google or Apple-controlled device, or you’re on a thin client tied to a cloud subscription, and you won’t own your tech anymore.

      Bezos’ ‘Give up your PC and rent from our cloud’ threat is sounding less and less like a threat and more and more likely to become reality.

      • Hemingways_Shotgun
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        1
        ·
        2 months ago

        I either use my banking website or go into city hall clerks office to pay it in person. I’ve never once had to go to the actual government website. It’s an option, but not mandatory.