Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

111–120 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#111
post #69

Earlier quoted context omitted.

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

How is this not grounds to be sued into oblivion by Google and Meta? They clearly violate ToS for profit. This is something I expect to find on a dark web forum where 0days are traded, not in public.

Violating ToS isn't illegal in most cases. Companies just put scary looking clauses in their ToS to discourage you from doing things they don't like.

Re: Google broke reCAPTCHA for de-googled Android users

#112
post #17

And soon desktop OSes will follow, if you don’t have TPM you won’t be able to browse half of the internet.

TPMs can also be based on free software and our own keys. It works well with Heads and Librem Key.

TPM with things like Heads are borderline zero security and theater compared to actually decent implementations on Android/iOS platforms, I doubt the big companies would rely on that. TPM in general on non Mac/Chromebook PCs is mediocre even from big OEMs.

Re: Google broke reCAPTCHA for de-googled Android users

#113

Time for some lawfare!

warfare*

https://en.wikipedia.org/wiki/Lawfare

> Lawfare is the use of legal systems and institutions to affect foreign or domestic affairs, as a more peaceful and rational alternative, or as a less benign adjunct, to warfare.

Re: Google broke reCAPTCHA for de-googled Android users

#114

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…

> https://ibb.co/X9Q6Y84

Wow, This is really bad :-(

I think this is just gonna make viewing internet without a phone significantly harder especially with archive.is and the likes.

Not sure, how relevant this is to the discussion but if it helps, I have made a project[0] which allows to archive archive.is pages on archive.org/wayback machine (this uses singlefile)

Perhaps something like this can be used by community at scale too. Also, I hope that archive.is does something to fix this issue of requiring QR code and hopefully it doesn't become a permanent issue.

[0]: https://smileplease.mataroa.blog/blog/htmlpipe-and-how-we-ca...

Re: Google broke reCAPTCHA for de-googled Android users

#115
post #53

Earlier quoted context omitted.

With the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.

One problem with these things is that businesses have minimal visibility on the amount of users they lose. On the opposite, if they see reports of many visitors not completing the captcha, they're likely to think "Wow so many bots!!! This defense nowadays is indispensable..!". Sometimes you need to pass a captcha even to contact them (if you want to tell them that you can't pass their captcha).

Luckily the marketplace of money will ensure that businesses who block their customers shrink and businesses who don't block their customers grow.

Re: Google broke reCAPTCHA for de-googled Android users

#116
To be fair, there are already apps that require a mobile phone to sign up, for example, VK, Telegram. And I think Google requires to scan a QR code to register account, so it is easier just to buy a Google account on a black market if you need it for some purpose.

Nobody trusts web browsers nowadays.

Re: Google broke reCAPTCHA for de-googled Android users

#117

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

Stop visiting sites and using services that use reCAPTCHA. Problem solved.

I'd love to, but I'd not be able to visit many sites anymore thanks to Cloudflare...

Re: Google broke reCAPTCHA for de-googled Android users

#118
post #75

Earlier quoted context omitted.

Indeed, I generally favor being conservative with regulations because they can genuinely impede progress and can be really hard to change or remove when they're bad, but this is an issue that we need regulation for. It's just too much in the interest of big tech to lock us down and strip us of our freedom of compute. Short of regulation. Unfortunately I see the regulatory environment more likely to go the other way o…

One unfortunate aspect of the entire problem: Go back, let's say 10, 15 or 20 years, when forces were a bit more balanced than today. When all these issues were already quite obvious, but probably somewhat easier to solve. The same people that cry loudly today were completely ignoring all these issues. Actively. And when someone came up with them, that guy was just an idi*t, disturbing the good mood. Right? I can sti…

So just to clarify, you also didn't solve anything but you want everyone to know you told them so and you were smarter?

> If you are one of them, you know what I'm talking about. I don't refer to you. But to the other 99.x%.

Reminds me of Facebook engagement bait

Re: Google broke reCAPTCHA for de-googled Android users

#120
post #87
post #69

Earlier quoted context omitted.

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

Why is every startup using that same Serif font now, Garamond or whatever. Is it an LLM design phenomenon? Its kinda ruining that font style for me. Also $1,500 a month for 10 "influencers" is wild. This doesn't seem that sophisticated unless they're doing something special to increase trust scores of accounts. They say they have "in house warming algorithm" which honestly doesn't inspire confidence for me. Whats fun…

I think the font is mimicking old Apple ads, eg: https://i.insider.com/5bf8592eb73c284de50e2f28
Post reply on HN