archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…
What? Don't Cloudflare literally have their own CAPTCHA service? Why are they using reCAPTCHA?
Google broke reCAPTCHA for de-googled Android users
431–440 of 618 posts
Re: Google broke reCAPTCHA for de-googled Android users
#432Earlier quoted context omitted.
The trick is to define "privacy-preserving age verification" in an extremely narrow way that ignores any other privacy concerns. For example, imagine you put the same private key into the 'secure element' of every single iphone. You use code signing so that key is only unlocked when the phone is running unmodified iOS with all security updates. You use encryption and remote attestation for the front-facing camera and…
That key will get leaked. A key that has to go into every phone, even if done at the manufacturer and onto the TPM chip, will get out. Also even if it doesn't get leaked directly, the security of TPM chips is not absolute. Secrets from them can theoretically be extracted given an attacker with sufficient means and motivation. Normally nothing that's on a typical TPM chip would warrant a project of that magnitude, but…
Maybe? But biometric passports, chip-and-pin payment cards and SIM cards seem to do reasonably well. And Apple can always push out a mandatory software update that rotates the key, if they need to.
> You could swap out the actual phone camera hardware and sensors for a custom board that feeds the entire phone camera data of your choosing and it would be none-the-wiser.
Apple's 'TrueDepth' cameras are serialised and paired with the rest of the device. The touch ID sensors were before that too.
I don't know the precise details, but reports from people trying to repair devices independently of Apple are that the phone is very much the wiser.
e.g. https://support.apple.com/en-gb/120567 https://www.reddit.com/r/iphonehelp/comments/1dl38kq/iphone_...
Re: Google broke reCAPTCHA for de-googled Android users
#433Re: Google broke reCAPTCHA for de-googled Android users
#434Earlier quoted context omitted.
What? Don't Cloudflare literally have their own CAPTCHA service? Why are they using reCAPTCHA?
Never understand this anymore, it's genuinely one of the easiest services to pay to bypass automatically (literally 3-liner of JS), webmasters are becoming incompetent.
Re: Google broke reCAPTCHA for de-googled Android users
#435Earlier quoted context omitted.
What? Don't Cloudflare literally have their own CAPTCHA service? Why are they using reCAPTCHA?
Never understand this anymore, it's genuinely one of the easiest services to pay to bypass automatically (literally 3-liner of JS), webmasters are becoming incompetent.
In this case, the answer is right there in the question: You have to pay to bypass it.
Re: Google broke reCAPTCHA for de-googled Android users
#436Earlier quoted context omitted.
With the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.
> most human visitors will actually be unable to pass the CAPTCHA Most human visitors will never ever notice the change. reCAPTCHA is completely invisible for most human visitors because they are allowed to pass just by fingerprint. It's not like an average user is going to have to scan a QR code every time they visit a site via web browser. If it were like this then it would be a non-issue because no sane website wo…
Re: Google broke reCAPTCHA for de-googled Android users
#437Re: Google broke reCAPTCHA for de-googled Android users
#438Earlier quoted context omitted.
Parental controls on device are a better solution that work today and don't carry a risk of data breach.
They would be a solution if almost all parents used them, but parents don't want to socially isolate their kids since a lot of "social" activity is now on social media. It's kind of a prisoner's dilemma. There's not necessarily wrong. Despite the vapid and damaging nature of most popular online media, isolating a child from it might have even worse social consequences when their real-life peer groups discover that th…
The problem of "parents are negligent" is also solved by existing laws which have fines for parents who are negligent towards their children, and governments absolutely love collecting fines, so all the incentives are properly aligned.
Re: Google broke reCAPTCHA for de-googled Android users
#439Earlier quoted context omitted.
Parental controls on device are a better solution that work today and don't carry a risk of data breach.
Are they a better solution? Yes Do they work currently? Not really Are they too complex for the avg joe to work out. Unfortunately yes. (Something about the smartest bears and the dumbest humans)
Re: Google broke reCAPTCHA for de-googled Android users
#440Earlier quoted context omitted.
Ah yes, google, the company who notoriously doesn’t offer any customer support will definitely make way for such complaints.
Drop your sarcasm for long enough to see that "I won't use your app if I have to use Google" is not a complaint _to_ Google. The bank I was talking about were the worst net loser of customers in the UK last year (around -8000) They are making excuses but maybe they would care about why.