Google Cloud fraud defense, the next evolution of reCAPTCHA

cloud.google.com

100 points by unforgivenpasta 4 hours ago


devy - 5 minutes ago

I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over.

Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet.

Note2: yes, the `curl $URL | bash` installation approach is essentially just that, yet somehow became popular.

bramhaag - 3 hours ago

The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652

So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future.

No mention of device integrity verification yet, but the writing is on the wall.

driverdan - 2 hours ago

Any company that requires me to scan a QR code to make a purchase is losing my purchase.

semiquaver - 29 minutes ago

Serious question: what if you don’t have a (smart)phone?

xacky - 3 hours ago

The fact that mobile devices are now mandatory to prove "humanness" means that Google no longer trusts desktop/open platforms anymore.

tech234a - an hour ago

The QR code feature looks like it could be spoofed to become a Pegasus deployment method once people get used to them.

somebehemoth - 21 minutes ago

Can someone smarter than me make the argument of how this proves passkeys are evil because they will be used with changes like reCAPTCHA evolution to further lock down the internet?!

MichaelNolan - 2 hours ago

I’m trying to use my phone less and less. Ideally I’d like to even switch a dumb phone.

But tactics like this will make that nearly impossible if every website starts requiring a QR code scan on a authorized smartphone.

x3sphere - 26 minutes ago

I ditched reCaptcha and switched to Cloudflare Turnstile recently. It’s been a lot more effective. Not sure about this but I won’t be switching back for the time being.

PyWoody - an hour ago

What funny timing: After being hounded with CAPTCHAs every time I tried to search from the URL bar for the past week, not two hours ago I switched everything over to DDG. Great work, Google!

SoKamil - 3 hours ago

Google clearly wants only Google approved models to traverse the web.

arewethereyeta - 36 minutes ago

Two mdashes in the first sentence...hmm.

basch - an hour ago

Is this why google was repeatedly telling me I was displaying patterns of being a bot yesterday because I click too fast? I've never gotten the error message as many times as I did yesterday.

graphememes - 33 minutes ago

yeah im not doing that

aboringusername - 27 minutes ago

I suppose it's now become a default assumption every customer is going to own a smart phone that complies with this requirement?

It seems on iOS you'll even need to download an application, which is quite a bit of friction.

In the current economic times, adding minutes onto the user journey is not going to result in increased sales, I suspect the data will prove the opposite.

Using a mobile device is bad enough as it is: TOTP, email, SMS codes, 3DS etc, while you can say this is part of the "flow", it's too much. I can see many abandoned journeys from this.

mayama - 3 hours ago

The site doesn't mention this. But, are they locking down QR code auth for only safetynet authenticated devices and with mobile number verification?

oybng - 32 minutes ago

just how evil can google be?

eddy-sekorti - an hour ago

Thanks for sharing

stupidgeek314 - 3 hours ago

Why can't an AI scan the QR code? Just fire up an emulator if necessary

amazingamazing - 2 hours ago

How are people stopping bots reliably?

ifh-hn - 2 hours ago

Can I confirm that this is more shit from Google trying to lock people into their ecosystem (or Apples) under the guise security?

arian_ - 3 hours ago

Google building harder walls against bots while simultaneously building AI agents that need to get through them is peak 2026.

scotty79 - 39 minutes ago

"This AI-resistant mitigation challenge to prove human presence is designed to make automated fraud economically unviable."

Oh, you sweet, summer child.

mrguyorama - 2 hours ago

Google and the reCAPTCHA network aren't even that good with fraud prevention. You would think being literally omniscient over the whole internet would make it trivial to catch account takeovers, and Gmail has a proven track record at resisting account takeover, but when we tried to integrate their fraud signals, they were worthless, worse than the rest of the industry, worse than our homegrown trash from a decade ago.

Because Google doesn't actually care about preventing fraud, they just want the data you feed them and the fraud feedback you provide. It's all take, no mutual business.

LoganDark - 2 hours ago

Human verification via QR code does not mitigate labor farms.

liamwei - an hour ago

[flagged]

kajman - an hour ago

This would not have ever been announced while Lina Khan was running the FCC.