cross-posted from: https://lemmy.ml/post/47972724

i encountered this for the first time today while attempting to read something on archive.today.

i confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.

the old type of captcha remains available too, for now:

screenshot of text: Important: Mobile verification for Google Cloud Fraud Defense is an experimental challenge type in Preview. Visual and audio challenges are available as alternatives for users who can't complete mobile verification. To use them, click the Visual  or Audio  buttons.

  • dajoho@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    7 days ago

    This is step one.

    Step two is id verification via play services before you’re even allowed to scan the QR code.

    This is going to erode privacy as we know it on the internet and I can’t see any feasible escape.

  • Snot Flickerman@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    167
    ·
    14 days ago
    1. People without a mobile device are fucked out of being able to pass a captcha

    2. As if this isn’t a way for them to associate multiple sessions on multiple specific devices with one another, this is just another avenue for data collection, period. Hidden under the guise of “more secure.”

    • Chulk@lemmy.ml
      link
      fedilink
      English
      arrow-up
      60
      ·
      14 days ago

      I imagine scammers are already thinking of ways to use this for phishing too

    • Corngood@lemmy.ml
      link
      fedilink
      arrow-up
      21
      ·
      13 days ago

      You don’t have to drink a verification can, but you do need to buy a verification phone.

    • adarza@lemmy.ca
      link
      fedilink
      English
      arrow-up
      11
      ·
      14 days ago

      i have one. but it isn’t android, or ios, or ‘smart’ in any way. it doesn’t even text. it’s just a telephone that fits in my pocket and connects to the cellular networks. it’s all i want. it’s all i use. it’s all i’ve needed ever since i got my first one about 25 years ago.

      • leadore@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        13 days ago

        Same! Except mine does do SMS text and has the other flip phone stuff like alarms, timer, calendar.

      • explodicle@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        13 days ago

        Don’t worry you’re included. Simply visit one of our Accessibility Centers between 8am-9am on odd Wednesdays, with a valid birth certificate, filled-out form from here, and a notarized Charizard.

    • MrKoyun@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      13 days ago

      It really should be illegal to build systems that require a user’s access to any unrelated technology. You shouldn’t be forced to have a phone to pay a parking fee or to get on the bus. You shouldn’t need an app to charge your car. You shouldn’t need to use proprietary software from one spesific company to pass a captcha on a random site.

  • brvslvrnst@lemmy.ml
    link
    fedilink
    arrow-up
    68
    ·
    14 days ago

    Nice captcha. Would be a shame if someone intentionally injected malicious code that had users scan a QR code under the guise of security.

    • unfinished | 🇵🇸@lemmy.ml
      link
      fedilink
      arrow-up
      13
      ·
      13 days ago

      It is a paywall, you just pay with your data. Except Google gets the revenue and not the website so maybe a second paywall will be “necessary”

  • antonim@lemmy.world
    link
    fedilink
    arrow-up
    37
    ·
    13 days ago
    1. Hype up AI.

    2. Everyone starts scraping the internet to obtain training data for their AI.

    3. To block the scrapers, countless sites implement stricter bot detection tools.

    4. The owners of the bot detection tools now effectively hold all of the internet by its throat, deciding who can access what and extorting more and more data from you to verify you’re human.

    Fucking genius.

  • Hemingways_Shotgun@lemmy.ca
    link
    fedilink
    English
    arrow-up
    33
    ·
    13 days ago

    Any website that chooses to use this service will simply not get my traffic. If enough people feel the same, those websites will lose clicks and eventually tell Google to pound sand.

    Imagine the utter hubris on these fuckers to think that people will get a google device just to access a website.

    Or to think that an average user sitting at home would run to another room to grab their phone so they can verify themselves on the desktop just to visit blackcougar.com

    • ayyy@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      13 days ago

      1 year later

      Government website you have to use to pay your water bill: “Confirm you are a human…”

      • Hemingways_Shotgun@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        13 days ago

        I either use my banking website or go into city hall clerks office to pay it in person. I’ve never once had to go to the actual government website. It’s an option, but not mandatory.

  • BradleyUffner@lemmy.world
    cake
    link
    fedilink
    English
    arrow-up
    33
    ·
    13 days ago

    No malicious site would ever fake this kind of flow in order to get someone to scan a dangerous QR code. Nope, that would never happen.

      • birdwing@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        24
        arrow-down
        1
        ·
        14 days ago

        Android ≠ Linux

        Android is based on a modified version of Linux, and owned by Google. Linux is independent.

        • Hawke@lemmy.world
          link
          fedilink
          arrow-up
          3
          arrow-down
          13
          ·
          13 days ago

          Android is Linux. Not all Linux systems are Android, but all Android systems are Linux.

          It’s not necessarily helpful to those on desktop Linux, but it is Linux if someone wants to be a purist about which operating systems run on their hardware.