Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

251–260 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#252

Earlier quoted context omitted.

It has a zero percent chance of reaching anyone who can do anything about it. You could try handwriting and posting a letter to their CEO. I think that sometimes works. Probably not very often but there are more than zero CEOs who read those letters.

REI is allegedly a co-op, maybe there's a committee or something it could be presented to?

Usually that just means the owners of the individual stores are the shareholders.

Re: Google broke reCAPTCHA for de-googled Android users

#253

So Stallman was right, after all?

Everyone, including Linus Torvalds, who rejected Stallman as too political or ideological, and advocated for "pragmatism" instead, is part of the reason we're where we are today. And it's going to get a lot worse, before it ever gets better.

Re: Google broke reCAPTCHA for de-googled Android users

#254

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

> I'm not going to give up reading the test results from my doctor You could just call them.

Oh just wait, the AI phone service on their side will be more than happy to complete your device attestation key challenge by touch tone. We have to make sure you are still you after all!

But in all seriousness, many services are making it difficult through to impossible to communicate outside of their web or app platforms. Call centres are expensive and messy, and it's now apparently acceptable as a society to treat customers/clients/whatever as adversaries so they can get away with making it hard to communicate with them.

Re: Google broke reCAPTCHA for de-googled Android users

#255

Earlier quoted context omitted.

Home Depot at least has a physical presence, which you can go and directly give some much-needed feedback to.

It has a zero percent chance of reaching anyone who can do anything about it. You could try handwriting and posting a letter to their CEO. I think that sometimes works. Probably not very often but there are more than zero CEOs who read those letters.

The point is to spread the word.

Re: Google broke reCAPTCHA for de-googled Android users

#256
post #190

After all the surveillance capitalism abuses over the last 2-3 decades of Web, it's a little late to be pushing back, but... should we start shunning individuals from companies who implement this? Whether it's from companies that create the tech, or companies that use it. In the orgy of money, we've had a kind of industry-wide sociopathic convention of individual engineers considering it perfectly OK to further surve…

I agree, wholeheartedly - lets get a list of the google engineers who worked on this. What do you propose we do with it?

Re: Google broke reCAPTCHA for de-googled Android users

#257

Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?

Cloudflare Turnstile, if you're already using Cloudflare (or not!): https://www.cloudflare.com/application-services/products/tur...

Re: Google broke reCAPTCHA for de-googled Android users

#258

Earlier quoted context omitted.

We don't yet know how the client side works, perhaps there will be a decompilation posted soon. It's possible this scenario is acceptable to them because it means they can still tie your access to something that's easier to ban without requiring a full account login.

They're tying my access to random users of a completely different service, and a different random user each time.

What are you implying? That it will become ineffective due to that?

That's possible... and they might change their mind if so, we will see.

I feel like it's a similar issue to when scrapers pretend to be an allowed-origin webpage in order to abuse "public" API keys for web services.

They could also require the mobile device to interact with the requesting webpage in some manner, similar to mutual PIN/codes for Bluetooth/TV pairing these days. That way bulk sharing of the codes would still require active participation from the device that requested it in the first place, likely with a short time limit.

Re: Google broke reCAPTCHA for de-googled Android users

#259

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least: - pretended that it wasn't all about invading peoples' privacy. - done a good ol' fashioned "but Apple does it" - pretended to be standards-oriented - advertised it as something completely transparent to the end-user Seems like that would've caused a lot less backlash while still achiev…

The article mentions that they use Private Access Tokens on iOS, so I'm not sure where you're getting the idea that they're "not adopting" them from

Re: Google broke reCAPTCHA for de-googled Android users

#260
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

Nice that there's bank to move to. We need regulations against such lock ups.
Post reply on HN