Google Cloud Fraud Defence is just WEI repackaged

Google has relaunched Web Environment Integrity (WEI)—a controversial 2023 proposal that faced industry-wide rejection—as Google Cloud Fraud Defense, a commercial CAPTCHA product that uses device attestation via Google Play Services to gate web access. This circumvents the open standards process that previously blocked WEI, concentrating control over internet access in Google's hands while creating security vulnerabilities (QR codes are easily spoofed and train users for phishing) and excluding privacy-focused users on hardened Android systems. For IT organizations, this represents a strategic shift toward vendor lock-in and reduced interoperability that will fragment user access, increase support burden for QR-based authentication, and expose enterprises to social engineering risks.

Hacker News3 min read
Read full article
Google Cloud Fraud Defence is just WEI repackaged
Google has relaunched Web Environment Integrity (WEI)—a controversial 2023 proposal that faced industry-wide rejection—as Google Cloud Fraud Defense, a commercial CAPTCHA product that uses device attestation via Google Play Services to gate web access. This circumvents the open standards process that previously blocked WEI, concentrating control over internet access in Google's hands while creating security vulnerabilities (QR codes are easily spoofed and train users for phishing) and excluding privacy-focused users on hardened Android systems. For IT organizations, this represents a strategic shift toward vendor lock-in and reduced interoperability that will fragment user access, increase support burden for QR-based authentication, and expose enterprises to social engineering risks.