Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

271–280 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#271
post #26

Earlier quoted context omitted.

A parallel, fully public and accessible internet being widespread and available for anyone with a slight tinkering kick... Could actually be really awesome. Let the commerce-driven, corporatized hellhole that the modern web has become eat itself.

I love the vision, but I do wonder how the parallel internet will deal with DDoS levels of bot traffic. I hear ‘web of trust’ pretty often and I like the idea but that’s not anonymous or accessible either

How do personal blogs deal with the HN hug of death? In this increasingly-utopian vision, I imagine that being more widespread than (paid) DDOS attempts. There won't be any money to be made (banks, Paypal, etc. won't trust the "parallel web") and with the proliferation of synthetic training data I'm not sure how useful a target a bunch of blogs and smallweb sites would be.

Re: Google broke reCAPTCHA for de-googled Android users

#272

This isn't just about weirdos (like me) who run GrapheneOS. Huawei phones don't have Google Play services installed, or Xiaomi phones with MIUI China. That's what, a billion and a half phones that can't get to your website now? Amazon tablets don't have Google services either, which hints that the upcoming Amazon phones also might not work with this.

If you need access to both apps from China and websites/apps from outside China, non-Apple devices have been difficult before this, primarily due to push notification infrastructure.

This makes it more difficult. But I don’t think it matters given how difficult it was prior to this.

Re: Google broke reCAPTCHA for de-googled Android users

#274

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

> I'm not going to give up reading the test results from my doctor You could just call them.

Or ask for a print out.

Re: Google broke reCAPTCHA for de-googled Android users

#275

Earlier quoted context omitted.

Home Depot at least has a physical presence, which you can go and directly give some much-needed feedback to.

It has a zero percent chance of reaching anyone who can do anything about it. You could try handwriting and posting a letter to their CEO. I think that sometimes works. Probably not very often but there are more than zero CEOs who read those letters.

Maybe they'll figure it out when their revenue drops next quorter or the ones after that?

I was thinking in the same terms: you put up a QR capcha, you don't get my traffic and money. Just the amount of extra work needed, let alone the Google tracking turns me off. As if traffic lights, crosswalks and bridges weren't enough of a hassle.

Re: Google broke reCAPTCHA for de-googled Android users

#276

Earlier quoted context omitted.

Well, how does Tor or other services do it now?

Tor does it by being so painfully slow an unreliable that the only way you would use it is if there is a cocaine-style reward at the end of it.

> Tor does it by being so painfully slow an unreliable

I do 95% of my web browsing via Tor Browser and it is very tolerable, most circuits are fast enough for 1080p video (Youtube, Twitch livestreams, etc) without any buffering.

Here is a speedtest I ran just moments ago, I would hardly consider this "painfully slow": https://www.speedtest.net/result/19172283165.png

Of course this is a single tor circuit with an exit node, so speeds are slower when going directly to .onion sites, but the only real slowness comes from the latency and not throughput.

Re: Google broke reCAPTCHA for de-googled Android users

#277
post #254

Earlier quoted context omitted.

> I'm not going to give up reading the test results from my doctor You could just call them.

Oh just wait, the AI phone service on their side will be more than happy to complete your device attestation key challenge by touch tone. We have to make sure you are still you after all! But in all seriousness, many services are making it difficult through to impossible to communicate outside of their web or app platforms. Call centres are expensive and messy, and it's now apparently acceptable as a society to treat…

I was unable to book a doctors meeting through the clinic's website, so I declared "screw tech" and called their call center, which still worked better. The app just searched for the "first available spot" and never found anything. If they axe the call center I'm going to have to go to their place.

Re: Google broke reCAPTCHA for de-googled Android users

#278

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

worth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all

so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on

(just realized emacs bindings work in comments, nice, no ctrl-x tho)

Re: Google broke reCAPTCHA for de-googled Android users

#279

Earlier quoted context omitted.

There really isn't much of an option. Apple's just as bad if not worse.

> Apple's just as bad if not worse. Could you justify that? Because to me it seems like Apple isn't doing anything even like this.

Apple never allowed custom ROMs to begin with, so their device attestation feels more seamless: https://support.apple.com/en-us/102591
Post reply on HN