HN user

Benferhat

267 karma
Posts13
Comments166
View on HN

I believe he's talking about Diablo 2 (the timeframe works, and the game is notorious for duping), in which Blizzard provides shady third party companies with items, which are then sold to users.

If I'm not logged into a site a that I regularly use, I'm probably not logged into my email, either. In order to log into my favorite site with Passwordless, I have to log into my email as well. With my password. One login for the price of two, and I'm still using a password.

I found a demo[0] via this old forum thread from August[1].

Obviously there are privacy concerns. That being said, this looks like a boon for anyone interested in bot detection, as you can periodically challenge your users' humanity without getting too much in their way. Nice one, Google.

From the thread:

Implemented it successfully for a website. I have to say, it works great!

it also checks if html pages are changed at runtime and how many times you "reload" the page where the captcha is. When it thinks you are a bot a captcha popups, when entered, it got checked on googles servers if it's right and fills in a hidden input. When the user submits the form, the filled in captcha coded, again, will be verifed. [sic]

[0] http://www.google.com/recaptcha/api2/demo

[1] Edit: don't go to this url without adblock (see comment below). http://forum.ragezone com/f144/googles-captcha-recaptcha-1023607/

Tor Appliance 13 years ago

How are users protected from malicious exit nodes, assuming they're visiting sites unprotected by SSL?

Sure, sometimes their usernames are their primary keys. Even if the actual primary key is arbitrary, the primary identity is still exposed to the user, in that they know what their user account is, and which email addresses are linked to it.

> But it's one that's never exposed to the actual user.

Why not expose it to the user? Because then they'll want to change it? Are you talking about browser fingerprinting?

We already expose this on the user/email level, where users can link and log in with as many email addresses as they like, under one account (identifier).

> GAE in October?

AppEngine's deprecation policy:

7.2 Deprecation Policy.

Google will announce if we intend to discontinue or make backwards incompatible changes to this API or Service. We will use commercially reasonable efforts to continue to operate that Service without these changes until the later of: (i) one year after the announcement or (ii) April 20, 2015, unless (as Google determines in its reasonable good faith judgment):

# required by law or third party relationship (including if there is a change in applicable law or relationship), or

# doing so could create a security risk or substantial economic or material technical burden.

[0] https://developers.google.com/appengine/terms scroll down to 7.2