Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

41–50 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#41

Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.

Android literally is a Linux distro, though. Like, sure it has a weird userspace and is user hostile, but that doesn't make it not a Linux distro.

Re: Google broke reCAPTCHA for de-googled Android users

#42

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least: - pretended that it wasn't all about invading peoples' privacy. - done a good ol' fashioned "but Apple does it" - pretended to be standards-oriented - advertised it as something completely transparent to the end-user Seems like that would've caused a lot less backlash while still achiev…

Not Invented Here Syndrome?

Re: Google broke reCAPTCHA for de-googled Android users

#43

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> My understanding is that this new reCAPTCHA is basically just remote attestation.

Yes, somehow "parse this QR code" would not have made my top 500,000 list of 'tasks that a human can do more effectively than a computer'.

Re: Google broke reCAPTCHA for de-googled Android users

#44
post #28

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Google didn’t demand iPhone users install Google software to pass the test. Can de-Googled Android phones present themselves as iPhones?

Can they present themselves as... web browsers?

Re: Google broke reCAPTCHA for de-googled Android users

#45

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

I don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough".

I think it's most likely to be attested by Google remotely; they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone, officially to make better humanity assessments based on it all.

For people using a Google account it probably won't make a huge difference, in terms of data collected.

If that's how it would work, spoofing would probably be theoretically possible, but it would be easy for Google to detect attestations used by multiple people.

Let's not forget that this is an update to a very approximate system, absolute security is not (yet) required.

But there's a good chance that it will be extremely hard to sidestep, despite that.

Re: Google broke reCAPTCHA for de-googled Android users

#46

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

Stop visiting sites and using services that use reCAPTCHA. Problem solved.

With the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.

Re: Google broke reCAPTCHA for de-googled Android users

#47

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

Stop visiting sites and using services that use reCAPTCHA. Problem solved.

Yeah, live in a cave, and problem solved.

However much I hate it, right now among the sites using reCAPTCHA there are many that I strongly want to use.

Let's find a better solution please

Re: Google broke reCAPTCHA for de-googled Android users

#48
post #28

Earlier quoted context omitted.

> Google didn’t demand iPhone users install Google software to pass the test. Can de-Googled Android phones present themselves as iPhones?

Can they present themselves as... web browsers?

Yes, and then they'll get served a QR code that you have to scan on a phone Google approves of.

Re: Google broke reCAPTCHA for de-googled Android users

#49
I don't use Android right now and haven't used Google'd Android for almost a decade. And I won't. If this is the hill I die on, so be it.

I'm not going to use any sort of hardware attestation, especially one controlled by Google. You shouldn't either, even if you have an unrooted Google-certified Android phone.

Post reply on HN