Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

391–400 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#391

Earlier quoted context omitted.

No, a clean browser and IP with the combination of what fonts I have installed, how my video card renders a canvas and WebGL instance (which may be affected not just by the video card you have, but the driver version used with it), my screen size, and a few other system level items that come through may or may or may not be enough to uniquely identify you. Along with linking to a prior profile if you screw up one tim…

I appreciate the information-theoretic validity of your argument, but if you think that one of these firms cares enough about your buying preferences to burn enough compute to find that correlation then you either work for the CIA or are mistaken.

It doesn't take a lot of compute resources to have multiple profiles, and when evidence of a high assurance level (a referring URL that is known to designate a specific user of a major service) to link it with other profiles that also have that designation.

To me, that seems par for the course for any service that's generating profiles of browsing behavior and trying to make any sort of decisions based on it. It reduces cruft and duplicate profiles while also providing more accurate information. Why wouldn't it be done?

> the information-theoretic validity of your argument

The portion about canvas, WebGL and AudtioContext hashing is not theory at all, it's well known practice from years ago. Jest the other day here there was a story about some advertiser on Stack Overflow trying to use the audio hashing to tracking purposes.

Hell, if you get enough identifiable bits of entropy, you can probably assume weak to strong level matching using a bit-level Levenshtein distance that's low enough.

Re: Google’s new reCAPTCHA has a dark side

#392

Earlier quoted context omitted.

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

> sour grapes seriously?

search “HN levels.fyi”

Re: Google’s new reCAPTCHA has a dark side

#393
post #378

Earlier quoted context omitted.

They have no right to it, and I have every right to try to limit their visibility. That's entirely fair! But also: You have no right to use my website, and I have every right to limit your access. Recaptcha is simply part of this negotiation.

> You have no right to use my website Of course. > Recaptcha is simply part of this negotiation. It is only a negotiation if I know it is there.

You’re commenting on HN, you know it’s there.

Re: Google’s new reCAPTCHA has a dark side

#394

Earlier quoted context omitted.

> You could either stop using these services or How do you stop using a service when you have little or no indication that it does something like this before hand, and afterwards the privacy is already gone? If I use a site and view my profile page and the url contains aa account id or username and some google or facebook analytics is loaded, or a like button is sitting somewhere, how am I to know that before the pag…

You use something that blocks scripts (like uMatrix) with an aggressive ruleset. On some sites you'll need to allow things to make them work. If they are loading trackers from the same servers that they load content from, you can't do much without wasting more time than you want. I'd say it breaks most of the tracking though. More sites than you'd expect work without js or with first-party js only. It's annoying when…

This was already with uBlock Origin. Also tried combinations of Ghostery and Privacy badger. All of it made very little difference for panopticlick, and that's probably a low-bar compared to what's common these days.

Re: Google’s new reCAPTCHA has a dark side

#395

There are a lot of sites that are totally unusable on Firefox regardless how much you use ff. I do all my mobile browsing on FF yet when I try to use some websites I always get this Recaptcha failed error(1) while it works flawlessly on chrome though I never use it often. Try it, maybe it will happen for you too. Same happens on most sites which show you that "checking your browser" page via cloudflare too. The web i…

Also Google punishes Firefox users by forcing them to click on pictures 2-3 times more than Chrome.

Which I intentionally and repeatedly fail anyway, because I'm not training Google's AI so they can sell it for use in drone strikes.

If this reduces the world Google allows me to access, it doesn't diminish mine because of it.

Re: Google’s new reCAPTCHA has a dark side

#396
post #302

Earlier quoted context omitted.

Shouldn't open aggregate listing and blocking of botnets be effective? How many 10k node botnets are there? Also: egress hygiene should be a thing. Block subnets and ASNs if toxic behaviour is detected.

> How many 10k node botnets are there? About 10 years ago it was somewhere around 10 million bot computers. Obviously the distribution isn't uniform there, but that gives you an idea of the order of magnitude. Also that was 10 years ago, before smart fridges and tvs. So, possibly more now? I don't think "just block all the bots" is a feasible solution here.

Not how many bots, but how many botnets.

The nets themselves take resources (time, effort) to set up and maintain. Presumably they're engaged (at least for the purposes of generalised website defence, though specific niches such as targeted commerce fraud may not apply) in systematic behaviour, which leaves signatures.

Systemic cross-site collaborative detection. -- essentially what Google's CAPTCHA systems are, though there are others, such as CZ.NIC's Turris project -- could identify these, and via network-based domains of authority (ASN and CIDR assignments) assign reputations and target anti-fraud or anti-abuse countermeasures.

Durable, privacy-respecting reputation tokens might be another approach.

Present systems are far more primitive and reflect an earlier world-state.

Re: Google’s new reCAPTCHA has a dark side

#398

Earlier quoted context omitted.

I'm guessing their a-listers came up with something like this: // TODO: add impressive-looking math if (signedin && trackedEverywhere) { return 0.9 } else { return 0.7 } I think we give Google way too much credit for their talent. This is the same company that didn't feel like finishing their website for two decades and subsequently stole $75 million from their users even when Google knew [1]. The same company that s…

Good info. Thank you. And in keeping with recent revelations on Google's manipulation of search results, I think they have really gone beyond the pale. I un-archived my old iPhone two days ago and went back to iOS after the James O'Keefe/Project Veritas revelations. I now cannot, in good conscience, use anything Google. I always knew about the tracking and all that because, after all, they are an ad company. I'm now…

You know Project Veritas is a load of shit right?

Re: Google’s new reCAPTCHA has a dark side

#399

Earlier quoted context omitted.

How about our friends and family? Should we configure a VPN for them too? Btw the argument you just made applies to any form of surveillance or censorship. Just because your can still find functional VPN services for China, is China's great firewall OK? And what happens when web services start blocking VPNs? Netflix does it quite successfully. And I'm sure Cloudflare could provide such a service for free.

I’m not making a moral argument for the surveillance state, I wear Curve25519 on one arm and the word “citizenfour” on the other. I agree that there is a vast and almost impossible to regulate overreach by these companies. Your argument is extremely compelling. But when HN users complain about being spied on I smell a FAANG rejection letter.

> But when HN users complain about being spied on I smell a FAANG rejection letter.

You’re projecting Ben.

Post reply on HN