Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

171–180 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#171
post #49

I don't use Android right now and haven't used Google'd Android for almost a decade. And I won't. If this is the hill I die on, so be it. I'm not going to use any sort of hardware attestation, especially one controlled by Google. You shouldn't either, even if you have an unrooted Google-certified Android phone.

What do you use instead? iOS?

Re: Google broke reCAPTCHA for de-googled Android users

#172

It's a move to block competitor AI agents while securing access for your own, classic ladder kick. The market for autonomous agents providing services and doing online work will be gigantic so, unless you want your own bots locked out from ie properties guarded by Amazon, CloudFlare, Microsoft etc., you will need a bargaining chip.

As someone that uses AI agents, this makes me want to install a browser plugin for "public windows" that just archives everything I see, and then farms out clicks of content that are missing from those sites.

The result of this would be to upload it all to a bot-friendly alternative to archive.org.

Re: Google broke reCAPTCHA for de-googled Android users

#173
post #150

Earlier quoted context omitted.

Apple has their own remote attestation infrastructure and you will not be able to impersonate an Apple device without extracting private key material from the secure enclave of a legitimate Apple device or compromising Apple certificate authority private keys.

Is this actually available in Safari?

Since iOS 16, apparently

https://blog.cloudflare.com/eliminating-captchas-on-iphones-...

https://developer.apple.com/news/?id=huqjyh7k

Re: Google broke reCAPTCHA for de-googled Android users

#175
post #69

Earlier quoted context omitted.

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

How is this not grounds to be sued into oblivion by Google and Meta? They clearly violate ToS for profit. This is something I expect to find on a dark web forum where 0days are traded, not in public.

> How is this not grounds to be sued into oblivion by Google and Meta?

Because they don't care. It doesn't matter that it's AI slop, it generates views. And Google and Meta can bill advertisers for those views.

Zuckerberg is paying people to put AI slop Shrimp Jesus on facebook. (Not directly to platforms like this, but with the incentive structure)

Really, they're not just cashing in on the views of AI slop being put in front of boomers. They're cashing both ways; While the low end spam industry is merely guessing and iterating on whatever generates views, the more refined spammer does not leave the performance of their latest slop post up to chance, and just uses good old viewbotting. Viewbotting that these days, is mostly done on real devices. Which show ads, to the bots or underpaid developing world workers. Google and Meta'll still charge you for those impressions though.

The losers? People who sincerely try to use these platforms, and whatever idiot businesses are still paying for ads by the impression or click, rather than conversions that immediately generate revenue.

Re: Google broke reCAPTCHA for de-googled Android users

#176
post #69

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

When companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/

These companies would have to buy one phone per fake influencer.

Re: Google broke reCAPTCHA for de-googled Android users

#177

Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?

hcaptcha is pretty popular these days. It uses a very wide variety of traditional visual puzzles.

Re: Google broke reCAPTCHA for de-googled Android users

#179

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least: - pretended that it wasn't all about invading peoples' privacy. - done a good ol' fashioned "but Apple does it" - pretended to be standards-oriented - advertised it as something completely transparent to the end-user Seems like that would've caused a lot less backlash while still achiev…

"pretended" ... do they even care any more?

Re: Google broke reCAPTCHA for de-googled Android users

#180
post #82

I think it's possible to run the Play Services in an emulator, faking the device type. Google doesn't seem to use the platform attestation for now.

Treatment is not a cure.

Agreed. I'm just pointing out the possibility (for now).
Post reply on HN