Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

21–30 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#21
It's a move to block competitor AI agents while securing access for your own, classic ladder kick. The market for autonomous agents providing services and doing online work will be gigantic so, unless you want your own bots locked out from ie properties guarded by Amazon, CloudFlare, Microsoft etc., you will need a bargaining chip.

Re: Google broke reCAPTCHA for de-googled Android users

#22

Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.

It's the punishment for all the times people laughed at calling regular Linux "GNU/Linux".

Re: Google broke reCAPTCHA for de-googled Android users

#23
post #14

Earlier quoted context omitted.

whenever I can't access a website for various stupid blocks I fire up cloudflare warp and walk right through it use wireguard with wgcf in environments without cloudflare client yeah it's stupid we have to do this in 2026 but I guess cloudflare is the new AOL garden

You sir seem to have solved a problem many people here have. Would you care to elaborate a little on how you did it? It doesn't happen that often to me, but sometimes adblock setup I'm using results in such issues.

He just told you, he used cloudflare WARP. It's a "VPN" along the lines of NordVPN et al, but by cloudflare, so it gets special treatment by cloudflare's walled garden enforcement system.

Re: Google broke reCAPTCHA for de-googled Android users

#24

Time for some lawfare!

The Government reviewed the Google situation on behalf of you,

and on behalf of the Government,

and said “data, so piss off”:

https://abcnews.com/Technology/google-hit-antitrust-lawsuit-...

https://macdailynews.com/2026/02/04/u-s-files-appeal-in-goog...

Re: Google broke reCAPTCHA for de-googled Android users

#25
For Decades the huge tech companies basically faced no adversity whatsoever. Now for the first time in their existence the massive returned investments in AI they are experiencing ... we will call it pain.

I would say it will be interesting to see what they do but I think rent-seeking, oppression, human rights violations would be more apt.

They were of course trustworthy proviers while they were untouchable but now I know how things are gonna go.

Re: Google broke reCAPTCHA for de-googled Android users

#26
post #17

And soon desktop OSes will follow, if you don’t have TPM you won’t be able to browse half of the internet.

A parallel, fully public and accessible internet being widespread and available for anyone with a slight tinkering kick... Could actually be really awesome.

Let the commerce-driven, corporatized hellhole that the modern web has become eat itself.

Re: Google broke reCAPTCHA for de-googled Android users

#27
post #15

Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops. My ISP regularly changes everyone's IP, and I apparently share an ISP with people who suck, so I get flagged just trying to do all sorts of normal things. Some examples: - I've never bought anything from Etsy but I'm somehow banned from even viewing their site at all. - Discord immediately b…

> Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops. I had this problem recently with the Indeed website. (Cloudflare Captcha) Thanks to someone on Reddit, it was discovered that anyone using a Chromium based browser (Brave, Vivaldi, etc.) on Linux was being punished. Awfully frustrating having to set up a Virtual Machine just to be able to…

Why not just change your user agent string?

Re: Google broke reCAPTCHA for de-googled Android users

#28

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Google didn’t demand iPhone users install Google software to pass the test.

Can de-Googled Android phones present themselves as iPhones?

Re: Google broke reCAPTCHA for de-googled Android users

#29

Earlier quoted context omitted.

You sir seem to have solved a problem many people here have. Would you care to elaborate a little on how you did it? It doesn't happen that often to me, but sometimes adblock setup I'm using results in such issues.

He just told you, he used cloudflare WARP. It's a "VPN" along the lines of NordVPN et al, but by cloudflare, so it gets special treatment by cloudflare's walled garden enforcement system.

I wonder if iCloud private relay might also work. Apple probably negotiated some special treatment

Re: Google broke reCAPTCHA for de-googled Android users

#30
post #28

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Google didn’t demand iPhone users install Google software to pass the test. Can de-Googled Android phones present themselves as iPhones?

Apple has their own remote attestation infrastructure and you will not be able to impersonate an Apple device without extracting private key material from the secure enclave of a legitimate Apple device or compromising Apple certificate authority private keys.
Post reply on HN