Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

391–400 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#391

Earlier quoted context omitted.

Motorola + GrapheneOS next year could be an alternative. So far they've been relatively insulated from the changes that have been coming down from Google.

I'll be waiting. In the meantime, I'm currently using a low end Motorola moto g 5G 2023 which lets me turn off Play Services. Chrome and the Google Calendar don't run (really do need to find a replacement calendar), and I couldn't be happier. Motorola's interest in GrapheneOS makes me wonder if they did this on purpose.

For calendar, I now have my own local setup, with Tailscale

Calendar server: https://radicale.org/v3.html Sync: https://manual.davx5.com/

So, you run Radicale server, you can import Google Calendar.

Set up Davx5 on mobile to sync with the local server

Access from anywhere with Tailscale.

Re: Google broke reCAPTCHA for de-googled Android users

#392

Earlier quoted context omitted.

Possibly... but the extension of this to Android and Apple is going to be the entire internet shuts you out. And everything else will be a giant Dead Internet crawling with bots.

The sites that require you to log in are precisely the same ones that are crawling with bots. The personal internet or "small web" is, and still will be, full of real content. There are also lots of bot websites that are trying to be small web, but since it's an actual social network and not a giant pool everyone pours stuff into, they don't get traction. If you do find a website that seems to be human but links to a…

It's less about those sites than it is about government services, banking, healthcare, employment, etc

Re: Google broke reCAPTCHA for de-googled Android users

#393
post #367
post #345

Earlier quoted context omitted.

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

https://ageverification.dev/

> Unlinkability is achieved by design through Zero-Knowledge Proof cryptography see the "Privacy by design" section below.

Re: Google broke reCAPTCHA for de-googled Android users

#394
post #367
post #345

Earlier quoted context omitted.

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

It should be possible with zero knowledge proofs.

The problem is that while you might be able to trust the crypto, the government won't trust you to do the crypto entirely by yourself. And this introduces avenues for deanonymisation. Moreover, collusion between the government and the entity making the age check can also theoretically deanonimize.

It's a complicated problem.

We continue to seek a technological solution to a parenting problem.

Re: Google broke reCAPTCHA for de-googled Android users

#395
post #345

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Divorcing technical detail from how it is used does little good for humanity.

Re: Google broke reCAPTCHA for de-googled Android users

#396

Earlier quoted context omitted.

What's the best alternative for Google drive? I also went this route but Samba is a bit annoying sometimes

Syncthing is very nice.

Is not the same though. It requires downloading the entire shared folder. That doesn't work when I have 100+GB of files and I want to share it with my phone

Re: Google broke reCAPTCHA for de-googled Android users

#397

Earlier quoted context omitted.

Because the site can compare the user agent with navigator.platform, which your browser fills with great care.

That naturally implies we must patch the browser. "Source code? We don't need no stinkin' source code!"

That's what Russian underground hackers do to create so called "anti-detect" browsers, which can emulate different browser fingerprints. But they are commercial and closed-source.

Re: Google broke reCAPTCHA for de-googled Android users

#398

Earlier quoted context omitted.

I think you and I move in very different social circles... I would have no idea how, nor desire to purchase a Google account on the black market, and I do in fact still trust that my web browser can do TLS correctly.

I think you can just search 'buy google account' - it isn't illegal.

Sure but how do I know that the person I'm buying from legitimately owns the account? Won't scam me? Or try to con me out of my existing account? I'm just saying not everyone is as relaxed about that sort of thing.

Re: Google broke reCAPTCHA for de-googled Android users

#399
post #350
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

> One bank refused to work (even with Google services) so I moved bank Banks are implementing terrible "security" checks. Users of alternative OSes should be a lot more vocal: change bank, but also complain a lot to the offending one, and make sure to leave them a bad review on the Play Store. Actually people not using an alternative OS but caring about that should also leave bad reviews to those banks on the Play St…

When I had a jailbroken iPhone my bank app (HSBC) would detect it and show a warning but let you continue anyway at your own risk, which I thought was a reasonable compromise

Re: Google broke reCAPTCHA for de-googled Android users

#400
post #162

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

The other problem with this is that there are few CAPTCHA alternatives. CF turnstile is one, but of course that means Cloudflare owns even more of the web. HCaptcha is inaccessible and actively discriminatory against individuals with disabilities and refuses to change, to the point that I suspect the only way that they will do anything is to file a class-action against them and sue them into the ground. And I... Can'…

The answer that no one likes: make it cost a nominal amount of money.

Enough to make it so bots are expensive to run.

Post reply on HN