Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

281–290 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#281

Does anyone know what changed in iOS 16.5 that made Google stop requiring the app? To me it seems to correlate with Private Access Tokens, aka remote attestation by Apple. https://developer.apple.com/videos/play/wwdc2022/10077/

Possibly. And possibly the fact that breaking experience for iOS users would result in a massive backlash, while the volume of non-iOS/non-Android users is negligible in comparison. Some of them will convert to mainstream OSes, the rest will succumb.

Re: Google broke reCAPTCHA for de-googled Android users

#282

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

worth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on (just realized emacs bindings work in comments, nice, no ctrl-x t…

I was going to ask for more info on this collusion but you say it wasn't reported. And googling "chicxulub" just gives a volcano.

Is this speculation, or has it been confirmed somewhere?

Re: Google broke reCAPTCHA for de-googled Android users

#283
post #113

Earlier quoted context omitted.

warfare*

https://en.wikipedia.org/wiki/Lawfare > Lawfare is the use of legal systems and institutions to affect foreign or domestic affairs, as a more peaceful and rational alternative, or as a less benign adjunct, to warfare.

The parent is musing on the impossibility of Google being held accountable, as the government largely assents to this plan and will ostensibly use it for social control during times of protracted warfare (eg. right now).

Re: Google broke reCAPTCHA for de-googled Android users

#284

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

worth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on (just realized emacs bindings work in comments, nice, no ctrl-x t…

Colluded how?

Re: Google broke reCAPTCHA for de-googled Android users

#285
post #162

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

The other problem with this is that there are few CAPTCHA alternatives. CF turnstile is one, but of course that means Cloudflare owns even more of the web. HCaptcha is inaccessible and actively discriminatory against individuals with disabilities and refuses to change, to the point that I suspect the only way that they will do anything is to file a class-action against them and sue them into the ground. And I... Can'…

There are other captcha alternatives like Turnstile, for example Private Captcha, Altcha etc. - they are owned by mostly “small” independent companies, they are not visual captchas (proof-of-work based) and very accesssible.

Re: Google broke reCAPTCHA for de-googled Android users

#286

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least: - pretended that it wasn't all about invading peoples' privacy. - done a good ol' fashioned "but Apple does it" - pretended to be standards-oriented - advertised it as something completely transparent to the end-user Seems like that would've caused a lot less backlash while still achiev…

Private access tokens are also a repackaged WEI as far as I'm concerned.

Re: Google broke reCAPTCHA for de-googled Android users

#288
On becoming anti Google, I blocked Google's ASNs (shortcut to block all their IP addresses) on my router the other day as an experiment. It's a little eye-opening.

Obviously you immediately realise just how often you !g in DDG, use Google Flights, YouTube etc. Ok easy enough to fix

Then of course I can't use Play Store (Aurora didn't work either) so my phone would have eventually become quite obsolete

You can't compile many Go projects because the dependencies are pulled from Google

And if you had ALL of Google's ASNs that would include GCP and that's a whole other level of being cut off

Re: Google broke reCAPTCHA for de-googled Android users

#289
post #272

This isn't just about weirdos (like me) who run GrapheneOS. Huawei phones don't have Google Play services installed, or Xiaomi phones with MIUI China. That's what, a billion and a half phones that can't get to your website now? Amazon tablets don't have Google services either, which hints that the upcoming Amazon phones also might not work with this.

If you need access to both apps from China and websites/apps from outside China, non-Apple devices have been difficult before this, primarily due to push notification infrastructure. This makes it more difficult. But I don’t think it matters given how difficult it was prior to this.

What's wrong with Apple push notifications in China?

Re: Google broke reCAPTCHA for de-googled Android users

#290
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

If you don't mind me asking, what Bank? I've resolved that this phone will be my last googled phone, and my next will be GrapheneOS.

Halifax UK. It just refuses to work so I left it (Graphene is more secure, so forcing less security for the sake of tracking is off the cards). All the other banks so far say they won't work without Google services but if I click OK they work
Post reply on HN