Paypal Payments Plugin Doesn’t Understand Fraud Prevention
-
Look, the site I was working on isn’t necessary because this is all back end.
tl;dr: Google’s captcha requires having an account for their “cloud” service full of bots, and seems to think anyone with an adblocker, thus probably not running bots and less likely to have a browser full of malware, is a higher risk. Other captchas could be an option…If they were let into the endpoints it seems. Reminders to increase security measures is good, but that’s mostly things like preventing XSS injectors, ensuring folks have SSL certificates, and avoiding OAUTH2 if at all possible. Captchas have their use, sure, but there’s no reason why it has to be google’s other than paypal only allowing google’s captcha access to certain data. There’s better ways to prevent fraud, and I would hope wordpress devs know this.
The longer version:
Went to go update site, got a terrifying sounding banner about needing google’s captcha or payment processors would deem my site and business high risk. Was anxious, but went to turn it on, but oh I need site keys. Weird. I go through the links, am confused about why the form isn’t giving me site links, then look into google cloud. Oh joy. Captcha is now part of Google’s attempts to force its genAI on people.
Took a moment to collect myself, because I am well aware of the risks of being high risk, and went digging. And…Found that google’s captcha has a crawler that “reduces the need to find a giraffe” so to speak. Weird, I hadn’t noticed only oh wait. My antitrackers and adblockers that keep my browser and computer safe from malware would also prevent google’s little bot from working. Ah. Yeah, well, I don’t want to put a google bot on anyone’s screen, only now we have two problems.
- Both paypal payment plugins have this banner that does not go away. Neither has an option to put a non-google captcha option.
- The other payment plugins might get cranky about this “preventing fraud” issue as well.
Okay potentially a third problem in that these blocks are more annoying than squarespace’s. Anyways. I went and found some security plugins that would do a far better job of preventing fraud than google’s captcha service. Weird there’s regular reminders to “make your page easier for genAI to read” but no explainers on XSS injectors? No baseline security with zero premium features? No links to cybersecurity basics designed to help nontechies who may end up using word press know some basics?
Yeesh. As was said on reddit for awhile, “The Iranian Yogurt is not the issue here”. The Google Captcha isn’t really the issue here. It’s just a sign of a larger issue of demanding users who may not know about other resources use a specific company’s service when there are better and more effective options out there.
You must be logged in to reply to this topic.