Time for some lawfare!
Google broke reCAPTCHA for de-googled Android users
31–40 of 618 posts
Re: Google broke reCAPTCHA for de-googled Android users
#32My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…
Re: Google broke reCAPTCHA for de-googled Android users
#33Earlier quoted context omitted.
> Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops. I had this problem recently with the Indeed website. (Cloudflare Captcha) Thanks to someone on Reddit, it was discovered that anyone using a Chromium based browser (Brave, Vivaldi, etc.) on Linux was being punished. Awfully frustrating having to set up a Virtual Machine just to be able to…
Why not just change your user agent string?
Re: Google broke reCAPTCHA for de-googled Android users
#34Re: Google broke reCAPTCHA for de-googled Android users
#35Earlier quoted context omitted.
> Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops. I had this problem recently with the Indeed website. (Cloudflare Captcha) Thanks to someone on Reddit, it was discovered that anyone using a Chromium based browser (Brave, Vivaldi, etc.) on Linux was being punished. Awfully frustrating having to set up a Virtual Machine just to be able to…
Why not just change your user agent string?
Re: Google broke reCAPTCHA for de-googled Android users
#36My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…
Re: Google broke reCAPTCHA for de-googled Android users
#37Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.
The kernel is a Linux kernel. The userspace is very different from a typical Linux distribution.
And let's not pretend that we mean the kernel when we say Linux distribution
Re: Google broke reCAPTCHA for de-googled Android users
#38My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…
Stop visiting sites and using services that use reCAPTCHA. Problem solved.
Re: Google broke reCAPTCHA for de-googled Android users
#39I don't know why reclaimthenet hasn't embraced the obvious answer: Simply create a new smart device operating system with a fully disentangled cosmos of programs, libraries, APIs, app SDKs, hardware partners, drivers, trust networks, carrier agreements, app stores, documentation, conferences...
Re: Google broke reCAPTCHA for de-googled Android users
#40- pretended that it wasn't all about invading peoples' privacy.
- done a good ol' fashioned "but Apple does it"
- pretended to be standards-oriented
- advertised it as something completely transparent to the end-user
Seems like that would've caused a lot less backlash while still achieving the goal of having some form of device attestation -- but I'm guessing that's not the real goal.