Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

91–100 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#92
post #69

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

I'm assuming that's a troll / sarcasm / fake... But that could just be my last vestige of faith in humanity.

Edit: aaaand... That's another little sliver of my faith gone : https://www.theatlantic.com/podcasts/2026/04/how-fake-people...

Re: Google broke reCAPTCHA for de-googled Android users

#93

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

If you run a website, it seems trivial to forward the attestation to someone else by putting the same code up on your website, and getting their device banned from google instead of your own.

The domain in the attestation would be yours, so that wouldn't work

Re: Google broke reCAPTCHA for de-googled Android users

#94

Given the way Google is going I'm not sure if my next phone will be Android. I am fully aware that I am probably in the minority here. For me the trust is entirely gone.

There really isn't much of an option. Apple's just as bad if not worse.

Re: Google broke reCAPTCHA for de-googled Android users

#95

I don't know why reclaimthenet hasn't embraced the obvious answer: Simply create a new smart device operating system with a fully disentangled cosmos of programs, libraries, APIs, app SDKs, hardware partners, drivers, trust networks, carrier agreements, app stores, documentation, conferences...

and that is gonna be funded by who? anyone who is gonna fund that is gonna want their slice of the pie. we need regulation to keep big tech in line

I uh.. I think that was the (sarcastic) point.

Re: Google broke reCAPTCHA for de-googled Android users

#96
post #53

Earlier quoted context omitted.

With the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.

One problem with these things is that businesses have minimal visibility on the amount of users they lose. On the opposite, if they see reports of many visitors not completing the captcha, they're likely to think "Wow so many bots!!! This defense nowadays is indispensable..!". Sometimes you need to pass a captcha even to contact them (if you want to tell them that you can't pass their captcha).

i say technofeudalism, not sure i know what i'm writing about though

Re: Google broke reCAPTCHA for de-googled Android users

#97
Almost completely unrelated, but I recently helped out a very confused family member with deleting not one, but two Google Cloud accounts they had no idea existed, and that they only learned about from an email referencing reCAPTCHA getting integrated into some other Google product offering.

I have absolutely no idea what happened there. My best theory so far is that they clicked on some really, really wrong buttons when solving a captcha themselves while logged in to their Google account in the same browser. Bizarre.

Re: Google broke reCAPTCHA for de-googled Android users

#98
post #47

Earlier quoted context omitted.

Yeah, live in a cave, and problem solved. However much I hate it, right now among the sites using reCAPTCHA there are many that I strongly want to use. Let's find a better solution please

> Let's find a better solution please Is there an argument here that Google is creating a monopoly? Could this be challenged on similar grounds that forced Microsoft to recommend other browsers to users on Windows?

There is, but at least in the US neither party cares. They want to get rid of anonymity online, one to throw anyone who googles "trans" in jail, and the other because their biggest donors are tech companies that want to denonymize everyone.

Our antitrust laws have been toothless for decades, and both parties love billionaires controlling the rest of us with an iron fist.

GrapheneOS is looking more and more worth the headache that my limited free time generally does not like. I don't need Google to know my smut fanfiction is written by my IRL.

Re: Google broke reCAPTCHA for de-googled Android users

#99
post #69

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

[dead]

Re: Google broke reCAPTCHA for de-googled Android users

#100
post #69

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

How is this not grounds to be sued into oblivion by Google and Meta? They clearly violate ToS for profit. This is something I expect to find on a dark web forum where 0days are traded, not in public.
Post reply on HN