Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.)
It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way.
The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider.
The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system.
and the only realistic way to achieve that is to make the people using their service reconsider.
So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas."
The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately.
I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type.
They combine your browser fingerprint (what extensions you have installed, version, etc), your IP address, and how you move your mouse, how fast you click, etc. It's surprisingly accurate.
Depending on your configuration your experience will differ greatly.
As mentioned in another comment I made, Freetube relies heavily on either directly connecting to YouTube’s API or proxying through an Invidious instance, perhaps try a different Invidious instance, but in my case Freetube + Invidious works 9 times out of 10 for me.
There are two ways of using Freetube, either with YouTube’s APi or with Invidious’s APi.
When using YouTube’s APi you won’t get the same ad-blocking and proxying benefits compared to Invidious’s API.
One bonus of using Invidious is that your traffic is combined with everyone else’s who use that same instance, for example if you use https://inv.nadeko.net/ your traffic will be masked along side everyone else’s who happens to use that same instance making it harder for big corporations to track you, in this case Google.
I think he just left to go work on fulu, no bad blood as far as i'm concerned. Anyways grayjay is pretty good, and when the new newpipe comes out that might be an even better choice maybe (but who knows when that'll be?? Tell me).
Creating an infrastructure that could potentially ingest terrabytes of data per second, and then processing it into multiple resolutions, is a massive ask.
Especially for a new site that might not ever get picked up by users, much less creators.
I think the only people that have a hope in hell of having a success at starting a youtube competitor are the owners of the big porn sites, since they are in a similar, if much smaller than youtube business with regards to infrastructure demands and processing needs. . So they have the institutional knowledge and infrastructural inertia to get started easier than anyone else on the planet. assuming they want to do a SFW video site, which they may not want to do, and it'd probably be burdened forever with right wing outrage due to any tenuous, distant connection to the porn sites (even if its just porn money or porn owners)
Yes, every time the topic comes up, this same idea comes up of making individuals bear the financial burden of hosting and bandwidth, without an ounce of understanding how that will never, ever, create a viable youtube alternative.
And once those problems come up, someone will have the great idea of gathering people into collectives to lower the prices and increase bargaining power.
Then after that someone will have the idea of reducing costs by moving their individual videos into the same rack, so the costs of hardware, storage, maintenance go down and stability and uptime goes up.
and before long you arrive back at a youtube like platform, and you've just become the equivalent of techbro reinventing the concept of a train for the 380th time.
I think I know who you are talking about, I recall seeing something about her making more money posting on pornhub than youtube because of greater advertising sharing or something.
You make it sound nefarious, but its most likely just an ability to be more generous with the revenue sharing compared to something thats 300x its size.
I mean, you could just switch to porn exclusively.
Hey, maybe that was the plan all along! I just wanted to understand how to fix my car or watch cat videos and now I'm watching a video where some lady is stuffing herself full of, well, everything.
It’s a fairly common phrase. Language can change and have regional differences. This isn’t Quebec defending their weird version of French as the only “correct” way to speak.
Or turn on adblockers and support the people you watch directly (donate, patreon, merch, etc). It takes like $2/yr to replace the ad revenue that you would've generated for them (something like that).
Or use the alt platforms that creators create themselves when possible.
You can't escape youtube right now (as in there is no real alternative if you stop using it all together), but you can turn on adblockers (ublock), use 3rd party clients and give something directly to creators you watch a lot.
support your local public broadcasting stations, people.
And do you know which documentaries they don't have? The ones that are uploaded by their creators only to YouTube.
I watch plenty of Arte and I pay the fee but documentaries about video game speedruns etc. simply aren't on Arte (or PBS or Nebula). I watch those where they are: YouTube.
Well, you made a wrong claim that I merely corrected. Watch whatever wherever you want. Doesn't change the fact that the documentary creators I follow for the vast majority only upload to YouTube and those that also upload to Nebula offer a worse experience there.
Lets put it another way: it really is not the youtube that was interesting 20 years ago, and you gotta think that yes, most of it is mindless shit. Or "content" which is just as bad.
Sure I could dig around and waste time trying to find gold in the sea of crap but why bother.
And yes, the algorithms do work against you, that is well documented, no matter what you click on.
Yes somewhat related, but the algorithm is not trying to help you find related or interesting things. It is trying to find ways to keep you engaged. That is a very different thing.
It will slowly try to direct you to outrage, polarization, addiction loops, sensationalism and clickbaity videos. It amplifys misinformation because either people fall into believing it OR are so outraged by it they want to comment or rage at it.
Youtube has an incentive to do these things: more watch time = more ads served = more revenue.
So people will tell you: just curate what you watch! That fixes it!
If you are going to curate what you watch, you don't need an algorithm!
Didn't think about and I guess it's kind of true, happens all the time where I get suggestions that are very bias. But the algorithm has also helped me find good creators, those who's main goal is not to become milliners and good music too. I do spent a lot of time watching YouTube so the engagement thing works, but I don't watch adds so jokes on YouTube.
I dont understand how and why is the phone involved in this check. I assume its a link to a website that authenticates you (probably google), but why not open it in the browser its alread at? Like what recaptcha was already doing for the past decade?
A few years ago I was given a technical deep dive into Akamai’s bot detection systems. One area they were quite focused on were bots impersonating mobile devices, and in particular mobile apps. It’s commonplace for attackers to try to mimic the behavior of mobile apps because it often provides more direct access to the data they’re looking for than trying to scrape websites.
To counter this threat Akamai developed a library for their customers to incorporate into their apps. This library collects a bunch of haptic data from the mobile device, such as the tilt sensors, accelerometers, finger taps/swipes on the screen, and other available data. It then encrypts it and sends it along to Akamai along with the data the app sends. Akamai then analyzes that haptic data and uses it as part of their bot detection analysis.
It is VERY difficult for a computer to mimic the truly random way a mobile device moves in space, or the way your fingers tap/swipe on a screen. If you were asked to draw a straight line from the upper left corner to the bottom right corner of your smartphone, not only would it not be perfectly straight but it would be quite fluid in its randomness. Writing a computer program to simulate that would be very tough. You’re far more likely to get lots of short straight lines with jagged angles than something that looks like a human drew it. And computer algorithms can quickly analyze this sort of data and return a confidence score indicating if it appears to have been created artificially or not.
So my guess is that when that QR code is scanned it will launch a Google app that will collect some similar haptic data and send it off to Google along with a unique id for that captcha. Google will then quickly analyze that haptic data to determine if you’re a bot or not.
Ohh, I've never thought about phone authentication being superior due the amount of sensors it has. Thanks for explaining, it makes a lot of sense (and I hate it)
I think they can use remote attestation on the mobile device to prove that it's a physical device. They do that through Google Play Services or whatever the equivalent is on iOS. So, for instance, scanning the QR code on a custom ROM like lineage or GrapheneOS doesn't work.
Doesn't clicking on the headphones switch to an audio test like with regular captcha? That's what I do and it works first time instead of getting an endless number of images when I use VPN. The words you enter don't even have to be 100% correct.
105 Comments
gressen@lemmy.zip · 105 pts · 64d
Name the offending website please.
lemmyng@piefed.ca · 141 pts · 64d
Google. It's their recaptcha service doing that. The QR code validation also gets rejected if you're using a privacy oriented mobile OS like Graphene.
markz@suppo.fi · 50 pts · 64d
At the cost of conditioning people into following orders from random qr codes
dieTasse@feddit.org · 14 pts · 64d
you mean it was google,com? Or on which website was this recaptcha?
lemmyng@piefed.ca · -12 pts · 64d
Recaptcha is a service offered by Google. It doesn't matter on which site the user encountered the QR code verification request - the problem is with Google (the company.)
MartianSands@sh.itjust.works · 70 pts · 64d
It does matter, because that Google integration didn't happen by magic. Whatever the site is, they chose to do things that way.
The only way Google stops things like this is if they get actual pushback, and the only realistic way to achieve that is to make the people using their service reconsider.
kuberoot@discuss.tchncs.de · 1 pts · 63d
The screenshot looks like it might be a cloudflare verification page, which would put another layer of separation between the site owner and the QR system.
Axolotl_cpp@feddit.it · 2 pts · 63d
Cloudflare don't use reCaptcha, they use turnstile
dieTasse@feddit.org · 1 pts · 63d
Exactly this!
lemmyng@piefed.ca · -1 pts · 63d
So what exactly will naming the site achieve? If someone wants to boycott recaptcha (which I'm 100% onboard with, btw) they'll just not comply with the captcha and leave the site when they encounter it. On the other hand, someone who would not otherwise visit the site cannot reduce traffic to the site by direct action. Telling their friends "don't use that site, it uses recaptcha" is no more effective than telling them "don't use any site that requires you to do QR recaptchas."
sidebro@lemmy.zip · 21 pts · 64d
archive.is in this case
9bananas@feddit.org · 7 pts · 63d
are they fucking serious with this shit?
what the hell...
woelkchen@lemmy.world · 13 pts · 63d
Archive.is is a Russian propaganda bot net. Don't use it.
9bananas@feddit.org · 3 pts · 63d
ah, that explains it...i half-remembered that something is off about that site, but couldn't remember what it was...thanks for the heads up!
cows_are_underrated@feddit.org · 4 pts · 63d
They also launched DDOS attacks against multiple other sites (e.g. Wikipedia).
SystemDisc@feddit.org · 1 pts · 63d
What are good alternatives?
Axolotl_cpp@feddit.it · 3 pts · 63d
Ghost archive
wander1236@sh.itjust.works · 18 pts · 64d
It looks like a Cloudflare interstitial. I also don't think sites get to choose which challenge types show up in reCAPTCHA, so this is on Google.
fizzle@quokk.au · 20 pts · 64d
Isn't the site choosing to use recaptcha?
wander1236@sh.itjust.works · 7 pts · 63d
The site is using Cloudflare for DDoS protection, and unfortunately Cloudflare is probably the most effective tool for this. It also looks like it might be archive.org in the screenshot, and they've been dealing with a lot of DDoS attacks lately.
I don't think Google advertises "we force you to scan a QR code" as a feature of reCAPTCHA either, so it feels a little weird to me to blame the site for using a DDoS protection tool that in turn uses reCAPTCHA for human verification when Google randomly decides to add a new stupid challenge type.
VonReposti@feddit.dk · 5 pts · 63d
As far as I know, Cloudflare doesn't use reCaptcha. I think they use a version of hCaptcha running on their own workers.
laundry861@fedinsfw.app · 103 pts · 64d
None of these are about identifying if you're human, they're about identifying which human you are.
WizardofFrobozz@lemmy.ca · 1 pts · 62d
How does that work?
The QR code thing I understand, but what about the “select all the fire hydrants” captchas?
laundry861@fedinsfw.app · 2 pts · 62d
They combine your browser fingerprint (what extensions you have installed, version, etc), your IP address, and how you move your mouse, how fast you click, etc. It's surprisingly accurate.
WizardofFrobozz@lemmy.ca · 1 pts · 62d
But isn’t that like 99% browser fingerprint and also the case with just about anything you do online, not just captchas?
laundry861@fedinsfw.app · 1 pts · 61d
Browser fingerprint (mostly) identifies the device. The captcha is to narrow that down even further to the person.
wisdomsuccubus@thelemmy.club · 0 pts · 62d
Really
EisFrei@lemmy.world · 87 pts · 64d
Not to excuse Google's practices, but you can select the eye icon to continue training an AI to detect buses and bikes.
sidebro@lemmy.zip · 35 pts · 64d
Oh, thanks for letting me know. I missed that one, as it isn't all that clear that's what it does.
feannag@sh.itjust.works · 18 pts · 63d
I also use an extension called buster that automatically solves the audio accessible captcha challenge.
Tja@programming.dev · 6 pts · 63d
Ironic
DrunkAnRoot@sh.itjust.works · 48 pts · 63d
I tried watching some yt in librewolf made me do 5 captchas an i had to switch vpn location so fuck google
W3dd1e@lemmy.zip · 19 pts · 63d
I have degoogled but YT is the only thing I’m stuck with. The monopoly is too much to overcome.
ohshit604@sh.itjust.works · 9 pts · 63d
Freetube + Invidious
cows_are_underrated@feddit.org · 4 pts · 63d
For me freetube usually only works about 30% of the time.
ohshit604@sh.itjust.works · 2 pts · 62d
Depending on your configuration your experience will differ greatly.
As mentioned in another comment I made, Freetube relies heavily on either directly connecting to YouTube’s API or proxying through an Invidious instance, perhaps try a different Invidious instance, but in my case Freetube + Invidious works 9 times out of 10 for me.
cows_are_underrated@feddit.org · 1 pts · 62d
Do you have any instances you can suggest?
ohshit604@sh.itjust.works · 1 pts · 62d
I can really only recommend what the Invidious developers recommend, unfortunately some instance admins have chosen to disable their public APi to prevent abuse or (in my scenario) have restricted their instance to certain geolocations.
If you have a Canadian IP I don’t mind letting people leech off of my instance, shoot me a DM and I’ll give you my domain.
DarrinBrunner@lemmy.world · 3 pts · 63d
I use Freetube, what does Invidious do?
ohshit604@sh.itjust.works · 0 pts · 62d
There are two ways of using Freetube, either with YouTube’s APi or with Invidious’s APi.
When using YouTube’s APi you won’t get the same ad-blocking and proxying benefits compared to Invidious’s API.
One bonus of using Invidious is that your traffic is combined with everyone else’s who use that same instance, for example if you use https://inv.nadeko.net/ your traffic will be masked along side everyone else’s who happens to use that same instance making it harder for big corporations to track you, in this case Google.
CeeBee_Eh@lemmy.world · 6 pts · 63d
If you're on mobile, check out the Greyjay app. It's promoted (sponsored?) by Louise Rossman
Justifier@lemmy.world · 2 pts · 63d
Apparently there was some fallout with futo and him
Not sure at all about the details, but yeah he definitely backed them. Not sure if he still does though
dogs0n@sh.itjust.works · 1 pts · 63d
I think he just left to go work on fulu, no bad blood as far as i'm concerned. Anyways grayjay is pretty good, and when the new newpipe comes out that might be an even better choice maybe (but who knows when that'll be?? Tell me).
Justifier@lemmy.world · 1 pts · 62d
I keep both newpipe and grayjay on my devices for when the other breaks
Tend to favor grayjay though because for whatever reason it usually works better for me
LavaPlanet@sh.itjust.works · 1 pts · 62d
Is that only on android?
CeeBee_Eh@lemmy.world · 1 pts · 62d
Ya, there's no way Apple would allow it in their app store
A_Random_Idiot@lemmy.world · 6 pts · 63d
Creating an infrastructure that could potentially ingest terrabytes of data per second, and then processing it into multiple resolutions, is a massive ask.
Especially for a new site that might not ever get picked up by users, much less creators.
I think the only people that have a hope in hell of having a success at starting a youtube competitor are the owners of the big porn sites, since they are in a similar, if much smaller than youtube business with regards to infrastructure demands and processing needs. . So they have the institutional knowledge and infrastructural inertia to get started easier than anyone else on the planet. assuming they want to do a SFW video site, which they may not want to do, and it'd probably be burdened forever with right wing outrage due to any tenuous, distant connection to the porn sites (even if its just porn money or porn owners)
tristynalxander@mander.xyz · 3 pts · 63d
A_Random_Idiot@lemmy.world · 3 pts · 62d
Yes, every time the topic comes up, this same idea comes up of making individuals bear the financial burden of hosting and bandwidth, without an ounce of understanding how that will never, ever, create a viable youtube alternative.
And once those problems come up, someone will have the great idea of gathering people into collectives to lower the prices and increase bargaining power.
Then after that someone will have the idea of reducing costs by moving their individual videos into the same rack, so the costs of hardware, storage, maintenance go down and stability and uptime goes up.
and before long you arrive back at a youtube like platform, and you've just become the equivalent of techbro reinventing the concept of a train for the 380th time.
tristynalxander@mander.xyz · 2 pts · 62d
A_Random_Idiot@lemmy.world · 2 pts · 62d
Thats not a youtube alternative then. Its a torrent hub 🙄
tristynalxander@mander.xyz · 2 pts · 62d
impairedimperator@lemmy.zip · 2 pts · 63d
Wasn't there some professor that started uploading actual educational non-porn lectures on pornhub a while back?
A_Random_Idiot@lemmy.world · 4 pts · 63d
I think I know who you are talking about, I recall seeing something about her making more money posting on pornhub than youtube because of greater advertising sharing or something.
Whats_your_reasoning@lemmy.world · 3 pts · 63d
And yet we’re having shit get censored everywhere else because aDvErTiSeRs. Clearly something doesn’t add up here.
A_Random_Idiot@lemmy.world · 1 pts · 63d
You make it sound nefarious, but its most likely just an ability to be more generous with the revenue sharing compared to something thats 300x its size.
cows_are_underrated@feddit.org · 2 pts · 63d
Afaik pornhub actually pays way more than YouTube. There are also lots of people uploading SFW content to the hub.
blargh513@sh.itjust.works · 1 pts · 62d
I mean, you could just switch to porn exclusively.
Hey, maybe that was the plan all along! I just wanted to understand how to fix my car or watch cat videos and now I'm watching a video where some lady is stuffing herself full of, well, everything.
Big porn wins again dammit!
NewNewAugustEast@lemmy.zip · 1 pts · 63d
Yeah but hosting your self isn't that big a deal depending on your host. At least until you get into the millions of views.
A_Random_Idiot@lemmy.world · 3 pts · 63d
We're talking about youtube competition, self hosting isnt ever going to compete with youtube.
corsicanguppy@lemmy.ca · -13 pts · 63d
No, it's not. It's a massive request. When you punch out and leave the car lot, be sure to use regular English.
mic_check_one_two@lemmy.dbzer0.com · 7 pts · 63d
It’s a fairly common phrase. Language can change and have regional differences. This isn’t Quebec defending their weird version of French as the only “correct” way to speak.
A_Random_Idiot@lemmy.world · 5 pts · 63d
That thar dude frum lemmy.ca, Imma laff ifn he done be Quebecois
crater2150@feddit.org · 2 pts · 63d
What's "regular English"? Only words you personally know? https://www.oed.com/dictionary/ask_n1?tab=meaning_and_use
LordCrom@lemmy.world · 1 pts · 62d
Use a VPN in Albania. No signin, no ads, its great
NewNewAugustEast@lemmy.zip · -1 pts · 63d
I just quit watching it a few months ago. No big deal, it's all crap and mindless shit anyways.
woelkchen@lemmy.world · 14 pts · 63d
If you click on mindless shit, the algorithm serves you mindless shit. I get documentaries. 🤷
GreenKnight23@lemmy.world · 4 pts · 63d
you know who else has documentaries?
PBS.
support your local public broadcasting stations, people.
dogs0n@sh.itjust.works · 3 pts · 63d
Or turn on adblockers and support the people you watch directly (donate, patreon, merch, etc). It takes like $2/yr to replace the ad revenue that you would've generated for them (something like that).
Or use the alt platforms that creators create themselves when possible.
You can't escape youtube right now (as in there is no real alternative if you stop using it all together), but you can turn on adblockers (ublock), use 3rd party clients and give something directly to creators you watch a lot.
And you can support PBS in addition if you want.
woelkchen@lemmy.world · 2 pts · 63d
And do you know which documentaries they don't have? The ones that are uploaded by their creators only to YouTube.
I watch plenty of Arte and I pay the fee but documentaries about video game speedruns etc. simply aren't on Arte (or PBS or Nebula). I watch those where they are: YouTube.
NewNewAugustEast@lemmy.zip · 1 pts · 63d
I just avoid algorithms. If I want documentaries there are places for those.
woelkchen@lemmy.world · 4 pts · 63d
Well, you made a wrong claim that I merely corrected. Watch whatever wherever you want. Doesn't change the fact that the documentary creators I follow for the vast majority only upload to YouTube and those that also upload to Nebula offer a worse experience there.
NewNewAugustEast@lemmy.zip · 1 pts · 62d
Lets put it another way: it really is not the youtube that was interesting 20 years ago, and you gotta think that yes, most of it is mindless shit. Or "content" which is just as bad.
Sure I could dig around and waste time trying to find gold in the sea of crap but why bother.
And yes, the algorithms do work against you, that is well documented, no matter what you click on.
Amdouni@lemmy.ml · 1 pts · 45d
What I like about the algorithm is that it suggest you related content (usually).
NewNewAugustEast@lemmy.zip · 1 pts · 45d
Yes somewhat related, but the algorithm is not trying to help you find related or interesting things. It is trying to find ways to keep you engaged. That is a very different thing.
It will slowly try to direct you to outrage, polarization, addiction loops, sensationalism and clickbaity videos. It amplifys misinformation because either people fall into believing it OR are so outraged by it they want to comment or rage at it.
Youtube has an incentive to do these things: more watch time = more ads served = more revenue.
So people will tell you: just curate what you watch! That fixes it!
If you are going to curate what you watch, you don't need an algorithm!
Amdouni@lemmy.ml · 1 pts · 45d
Didn't think about and I guess it's kind of true, happens all the time where I get suggestions that are very bias. But the algorithm has also helped me find good creators, those who's main goal is not to become milliners and good music too. I do spent a lot of time watching YouTube so the engagement thing works, but I don't watch adds so jokes on YouTube.
plutopos@lemmy.zip · 2 pts · 63d
I tried using Konqueror once, but Cloudflare websites (like WineHQ) would verification loop me. Niche browsers are discriminated against
trackball_fetish@lemmy.wtf · 0 pts · 62d
Doesn't yt-dlp still work? Could go that route, then just delete the video if you don't want it afterwards
psx_crab@lemmy.zip · 36 pts · 64d
Man i will nope out of this website so quick.
Redjard@reddthat.com · 26 pts · 63d
Beware it'd be quite easy to decensor that qr from the image.
45o3b@lemmy.ml · 24 pts · 64d
I'll get hate for referencing a solution that involves AI, but this looks promising: https://github.com/Captcha-Sonic/CaptchaSonic-Extension
lemmyman@lemmy.world · 10 pts · 63d
Lmao so the captchas don't even do anything anyway. Except harass us.
9bananas@feddit.org · 6 pts · 63d
that's been true for years now:
captchas have been a mild inconvenience for bots for like 10 years.
they are, like so many things, pure security theater...not actual security.
ozymandias117@lemmy.world · 6 pts · 63d
They were introduced as a way to crowdsource OCR
Google would give two words, one they knew and one they didn't
4chan screwed with them back in the day by all giving the same wrong answer on the second word so their OCR would scan wrong
AssaultPepper@lemmy.dbzer0.com · 8 pts · 64d
This is a good use of AI.
muhyb@programming.dev · 11 pts · 64d
Eye for an eye
MonkderVierte@lemmy.zip · 22 pts · 64d
Recaptcha users will experience some visitor losses.
Frenchgeek@lemmy.ml · 18 pts · 62d
sidebro@lemmy.zip · 2 pts · 61d
Such a gem of a movie
MrSoup@lemmy.zip · 8 pts · 64d
I see phishing opportunity here. Thanks Google
Maxxie@piefed.blahaj.zone · 7 pts · 64d
I dont understand how and why is the phone involved in this check. I assume its a link to a website that authenticates you (probably google), but why not open it in the browser its alread at? Like what recaptcha was already doing for the past decade?
Im so confused
IphtashuFitz@lemmy.world · 14 pts · 63d
A few years ago I was given a technical deep dive into Akamai’s bot detection systems. One area they were quite focused on were bots impersonating mobile devices, and in particular mobile apps. It’s commonplace for attackers to try to mimic the behavior of mobile apps because it often provides more direct access to the data they’re looking for than trying to scrape websites.
To counter this threat Akamai developed a library for their customers to incorporate into their apps. This library collects a bunch of haptic data from the mobile device, such as the tilt sensors, accelerometers, finger taps/swipes on the screen, and other available data. It then encrypts it and sends it along to Akamai along with the data the app sends. Akamai then analyzes that haptic data and uses it as part of their bot detection analysis.
It is VERY difficult for a computer to mimic the truly random way a mobile device moves in space, or the way your fingers tap/swipe on a screen. If you were asked to draw a straight line from the upper left corner to the bottom right corner of your smartphone, not only would it not be perfectly straight but it would be quite fluid in its randomness. Writing a computer program to simulate that would be very tough. You’re far more likely to get lots of short straight lines with jagged angles than something that looks like a human drew it. And computer algorithms can quickly analyze this sort of data and return a confidence score indicating if it appears to have been created artificially or not.
So my guess is that when that QR code is scanned it will launch a Google app that will collect some similar haptic data and send it off to Google along with a unique id for that captcha. Google will then quickly analyze that haptic data to determine if you’re a bot or not.
Maxxie@piefed.blahaj.zone · 8 pts · 63d
Ohh, I've never thought about phone authentication being superior due the amount of sensors it has. Thanks for explaining, it makes a lot of sense (and I hate it)
ambitiousslab@feddit.uk · 8 pts · 64d
I think they can use remote attestation on the mobile device to prove that it's a physical device. They do that through Google Play Services or whatever the equivalent is on iOS. So, for instance, scanning the QR code on a custom ROM like lineage or GrapheneOS doesn't work.
snooggums@piefed.world · 15 pts · 63d
They want to force interaction with your phone so they can identify who you are.
Axolotl_cpp@feddit.it · 3 pts · 63d
And also to stop you from using not-approved phones and OSes
Luisp@lemmy.dbzer0.com · 7 pts · 64d
Scan to get hacked
Phantaloons@piefed.zip · 1 pts · 63d
Google's already on their phone. Consumers gladly pay for the priviledge of malware.
winkledinkle@sh.itjust.works · 7 pts · 62d
First time I saw that, I immediately suspected a malware attack.
If it's not, it soon will be.
Stopwatch1986@lemmy.ml · 6 pts · 63d
Doesn't clicking on the headphones switch to an audio test like with regular captcha? That's what I do and it works first time instead of getting an endless number of images when I use VPN. The words you enter don't even have to be 100% correct.
TryingToBeGood@reddthat.com · 6 pts · 62d
Wow. No.
Hubi@feddit.org · 6 pts · 64d
Not justifying this by any means but you can just click on the eye icon at the bottom to get the regular captcha.
snooggums@piefed.world · 7 pts · 63d
Vague option is vague.
Peter_Arbeitslos@feddit.org · 2 pts · 63d
Fröhlichen Kuchentag!
Hubi@feddit.org · 2 pts · 63d
Danke, dir auch!
chunes@lemmy.world · 2 pts · 58d
I don't have a mobile device. Guess I'm not human anymore.
ButteredBread@sh.itjust.works · 1 pts · 40d
NeatNit@discuss.tchncs.de · 0 pts · 64d
.... what?