I have a theory that as AI gets better and better at mimicking humans, the only way to differentiate humans from bots, is to identify the human. This may not even be a conscious development from the company.

For example, Google’s Recaptcha might be a big black box of AI models, that gets data about the user and spits out “human” or “bot”. These AI models already get a ton of data about the user, like mouse movements, scrolling behavior, and keyboard strokes (afaik Recaptcha tracks all of this, and Cloudflare will soon). What if at some point, Google realizes that the AI has evolved to identify users, tying them to long-standing Google accounts or government IDs, because it’s the most effective way to distinguish them from bots?

Google is already releasing the captcha that requires a Google-approved phone. That is also a privacy dead-end. But I wonder if Recaptcha and Cloudflare’s new Precursor captcha, are already deanonymizing people.

And even open source projects and websites are starting to adopt Anubis, and complaining about AI contributions and slop. It seems like even the open source world is crawling towards human verification. The future of privacy does not look bright.

  • hendrik@palaver.p3x.de
    link
    fedilink
    English
    arrow-up
    6
    ·
    6 days ago

    Probably some hardware-assisted attestation. All the phones, tablets and Windows laptops will get a small chip. It’ll send a cryptographic response (plus your advertiser ID) and a consortium of Google, Microsoft and a few others will come up with the magic to make it work. It’ll be very effective. Not really for you, you might not be legible to visit a website. But the advertisers will get a pretty accurate reading whether their ad was clicked on by a human or bot.

      • hendrik@palaver.p3x.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        5 days ago

        I’d say either some next generation of TPMs. Or some more software. I mean we already have these strange smartphone farms where one operator has some hundreds of phones and sends out spam, youtube comments and amazon reviews all day. They could embed it deeper into the operating system, read some sensors like the accelerometer and see if the phone is carried around by someone. That’d be more effective than some workarounds. And of course they need to cut off all old devices. I suspect Google is already working on it. But to this day I can still solve CAPTCHAs with my mouse, bypass the YouTube ads. And even my 15 year old LG TV can still play YouTube. I guess most important step is to be way more strict with people. And to fund some institution who’s in charge of the cryptography and keys. Or Google needs to buy Cloudflare, that’ll do it as well. 😅

    • hirihit640@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      Of course, they’ll claim it’s using “private compute” or other fancy technologies to ensure that the servers only run audited software that never extradites personal data. Though the auditors will be private third-parties that may as well just be arms of the government.

      • hendrik@palaver.p3x.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        6 days ago

        […] may as well just be arms of the government.

        … which in turn is largely an arm of the industry, these days 😅