cross-posted from: https://lemmy.ml/post/47972724

i encountered this for the first time today while attempting to read something on archive.today.

i confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.

the old type of captcha remains available too, for now:

screenshot of text: Important: Mobile verification for Google Cloud Fraud Defense is an experimental challenge type in Preview. Visual and audio challenges are available as alternatives for users who can't complete mobile verification. To use them, click the Visual  or Audio  buttons.

  • Snot Flickerman@lemmy.blahaj.zone
    Aquileo | link
    Aquileo | fedilink
    English
    Aquileo | arrow-up
    220
    ·
    2 months ago
    1. People without a mobile device are fucked out of being able to pass a captcha

    2. As if this isn’t a way for them to associate multiple sessions on multiple specific devices with one another, this is just another avenue for data collection, period. Hidden under the guise of “more secure.”

    • Prove_your_argument@piefed.social
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      50
      ·
      2 months ago

      Captcha has been one of the greatest google acquisitions ever.

      They acquired it under the guise of improving OCR and have since morphed it into an AI data farm (how else is google lens gonna know what objects are what?) and now total insight into a users every single action from desktop to mobile, tying it all together into a surveillance nightmare.

      I can guess the permissions that the recaptcha app needs now. Probably something akin to root access with all datapoints and considerations you could think of.

      • No1@aussie.zone
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        20
        ·
        2 months ago

        I used to always add one incorrect tile and skip one correct tile.(It would still pass)

        I thiught I was such a rebel lol

        Then I figured, they’d be stupid if they didn’t show the same image to multiple people…

        • Prove_your_argument@piefed.social
          Aquileo | link
          Aquileo | fedilink
          English
          Aquileo | arrow-up
          3
          ·
          2 months ago

          I’ve had many, many not traffic light and motorcycle/bicycle recaptchas. They’re probably leaning a bit into self driving learning the past few years.

          Lens has a lot more data points nowadays after everyone’s google photos was used for training for what, 10+ years at this point?

          Google harvested all human typed words 15 years ago with the google library project. They’ve been hoarding and processing data for models forever.

          • Lumidaub@feddit.org
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            1
            ·
            2 months ago

            I was being at least partly facetious because I rarely get anything but motorcycles and traffic lights and even then it’ll most likely ask me about buses or bridges. Not disagreeing that they’re hoarding data :)

      • MrKoyun@lemmy.world
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        3
        ·
        2 months ago

        The point with captchas is not really that bots can’t pass them, more that its too expensive to pass them consistently with a hurtfully large enough volume of bots.

        • HeHoXa@lemmy.zip
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          2
          ·
          Aquileo | edit-2
          2 months ago

          I’d heard of this strategy, like making it perform some kind of costly encryption that’s irrelevant to a human user but restrictively expensive for a bot army.

          But does decoding a QR code apply? I never really thought about it. I guess it’s an image, it’s at least a little big by comparison… but it’s also in a restricted, easy to capture spot and maybe could be minimized to a fairly small pixel set? Idk how many key pixels you need to parse a QR code… I guess I could Google

          *typo bit --> bot and bit --> big… I’m full of bit

          • MrKoyun@lemmy.world
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            2
            ·
            2 months ago

            I don’t know much about this new captcha system, but I feel like the challenge wouldn’t really be in the scanning of the qr code itself but more so on making the device you’re scanning with seem legitimate. They could check usage patterns, what apps are installed, how many accounts are added and are they actively used, location and sensor data, are the hardware specifications really unusual, are they constantly trying to complete random captchas… Stuff like that to tell apart a real user’s device from a bot or sandbox. The QR Code is probably just a random ID for which captcha instance the user is trying to pass.

            Also I just realised this but this is probably inconvenient as hell. Like I do NOT want to constantly be picking up my phone to scan QR codes when I’m trying to go around the Internet. What if my phone is on the other side of the house? I don’t want to get up and walk all the way over there! If this gets fully rolled out there may actually be a small dip on the amount of desktop users of websites because they just leave when they are hit wth this captcha instead of bothering to scan a code.

            • HeHoXa@lemmy.zip
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              1
              ·
              2 months ago

              Heard. We have a QR 2auth system for one of my work domains, and I let out an exasperated sigh every time I realize I have to get my phone out

    • adarza
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      14
      ·
      2 months ago

      i have one. but it isn’t android, or ios, or ‘smart’ in any way. it doesn’t even text. it’s just a telephone that fits in my pocket and connects to the cellular networks. it’s all i want. it’s all i use. it’s all i’ve needed ever since i got my first one about 25 years ago.

    • MrKoyun@lemmy.world
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      9
      ·
      2 months ago

      It really should be illegal to build systems that require a user’s access to any unrelated technology. You shouldn’t be forced to have a phone to pay a parking fee or to get on the bus. You shouldn’t need an app to charge your car. You shouldn’t need to use proprietary software from one spesific company to pass a captcha on a random site.