Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

141–150 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#142

Earlier quoted context omitted.

How is this not grounds to be sued into oblivion by Google and Meta? They clearly violate ToS for profit. This is something I expect to find on a dark web forum where 0days are traded, not in public.

Violating ToS isn't illegal in most cases. Companies just put scary looking clauses in their ToS to discourage you from doing things they don't like.

That's not true of course. There are hundreds of such cases with varying outcomes [0][1][2]

[0] https://en.wikipedia.org/wiki/Facebook,_Inc._v._Power_Ventur....

[1] https://en.wikipedia.org/wiki/MDY_Industries,_LLC_v._Blizzar....

[2] https://en.wikipedia.org/wiki/EBay_v._Bidder%27s_Edge

Re: Google broke reCAPTCHA for de-googled Android users

#143

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

> I'm not going to give up reading the test results from my doctor

You could just call them.

Re: Google broke reCAPTCHA for de-googled Android users

#144

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> My understanding is that this new reCAPTCHA is basically just remote attestation. Yes, somehow "parse this QR code" would not have made my top 500,000 list of 'tasks that a human can do more effectively than a computer'.

I'm sure some people still remember how to mentally decode QR codes and verify ECDSA signatures from Covid days. Public transit ticket inspectors in my city also seem to be quite proficient at it :)

Re: Google broke reCAPTCHA for de-googled Android users

#145
post #86
post #58

Earlier quoted context omitted.

It's all fun until you can't get paid because some fintech app doesn't work. That's why we need regulations. I don't see politicians ever going against an advertising company when they're customers.

Already happening. The official German identification app, AusweisApp, is designed exclusively for Android and Apple mobile devices

If it was developed by the government, shouldn't the source or an API be available? Surely third-party apps can be made in that case?

Re: Google broke reCAPTCHA for de-googled Android users

#146

Earlier quoted context omitted.

There really isn't much of an option. Apple's just as bad if not worse.

At least with an Android i have the option of Graphene, and have access to a terminal, and for now can sideload apps. With apple there's no choices, so I'll continue to take my chances with Android

Possibly... but the extension of this to Android and Apple is going to be the entire internet shuts you out. And everything else will be a giant Dead Internet crawling with bots.

Re: Google broke reCAPTCHA for de-googled Android users

#147
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

What's the best alternative for Google drive? I also went this route but Samba is a bit annoying sometimes

If you dont need filesharing, you can just setup wireguard, setup a network drive on your phone's files app.l, and then when connected it'll feel like native file browsing.

Re: Google broke reCAPTCHA for de-googled Android users

#148
post #118
post #75

Earlier quoted context omitted.

One unfortunate aspect of the entire problem: Go back, let's say 10, 15 or 20 years, when forces were a bit more balanced than today. When all these issues were already quite obvious, but probably somewhat easier to solve. The same people that cry loudly today were completely ignoring all these issues. Actively. And when someone came up with them, that guy was just an idi*t, disturbing the good mood. Right? I can sti…

So just to clarify, you also didn't solve anything but you want everyone to know you told them so and you were smarter? > If you are one of them, you know what I'm talking about. I don't refer to you. But to the other 99.x%. Reminds me of Facebook engagement bait

> Reminds me of Facebook engagement bait

If you say so. I don't know. I was never an active part of that big problem (so btw I also had nothing to "solve"). You were?

Re: Google broke reCAPTCHA for de-googled Android users

#149
post #45

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

I don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough". I think it's most likely to be attested by Google remotely; they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone, officially to make better humanity assessment…

> they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone

But anything your phone can possibly do in software can be spoofed, so how would that help?

Re: Google broke reCAPTCHA for de-googled Android users

#150
post #28

Earlier quoted context omitted.

> Google didn’t demand iPhone users install Google software to pass the test. Can de-Googled Android phones present themselves as iPhones?

Apple has their own remote attestation infrastructure and you will not be able to impersonate an Apple device without extracting private key material from the secure enclave of a legitimate Apple device or compromising Apple certificate authority private keys.

Is this actually available in Safari?
Post reply on HN