Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

451–460 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#451

Earlier quoted context omitted.

If you don't understand something, the first thing to do is try to understand it, before going to "the people who use this are incompetent". In this case, the answer is right there in the question: You have to pay to bypass it.

Sometimes, people just do dumb choices, there is nothing to understand except plain lazyness, there is better captchas, free, non-invasive, more secure, GDPR compliant and so-on that are also not covered by captcha-solving providers, so what's the positive argument about reCaptcha?

A very strong brand?

Re: Google broke reCAPTCHA for de-googled Android users

#453

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…

Even crazier is that there is nothing preventing agents from not using this. The hardware, signing, etc. can all operate as part of an autonomous agent stack. There is no benefit here to anyone.

Re: Google broke reCAPTCHA for de-googled Android users

#454
post #272

This isn't just about weirdos (like me) who run GrapheneOS. Huawei phones don't have Google Play services installed, or Xiaomi phones with MIUI China. That's what, a billion and a half phones that can't get to your website now? Amazon tablets don't have Google services either, which hints that the upcoming Amazon phones also might not work with this.

If you need access to both apps from China and websites/apps from outside China, non-Apple devices have been difficult before this, primarily due to push notification infrastructure. This makes it more difficult. But I don’t think it matters given how difficult it was prior to this.

Using apps based on Google Play Services may be impossible on those phones out of the box (not sure), but websites have no such dependency and most people don’t give a crap about push notifications from PWAs anyway so whether FCM works with the device matters little. Also doesn’t the web push API support different push services at registration time so those devices’ browsers can register their own vendor push server? (It’s been a while since I implemented web push myself, memory is fuzzy.)

This is blocking access to websites wholesale, so it’s on a whole different level.

Re: Google broke reCAPTCHA for de-googled Android users

#455
post #386
post #313

Earlier quoted context omitted.

How often are your emails being marked as spam, for others? A few years ago it read like there’s a whole science behind avoiding getting flagged. Is this easier now with agents aiding the setup?

Not the person you replied to, and it's impossible to know with certainty how often you're in someone else's spam, but very rarely. I had an issue with yahoo a couple of years ago that's all. The "it read like there's a whole science" is sadly a trope mostly repeated by people who have never tried because it gets upvotes on Reedit. There are some steps you have to take, but not many, and systems like Mox mailserver o…

You got me really interested here, I ran my own mailserver years ago and eventually just gave it up. I am getting rid of Google Workspace and have been planning a migration to Proton for two domains. But this sounds like a fun project. Any advice? I am going to check out Mox and Stalwart.

What providers are good hosting candidates, I have a website on DO, but from my understanding their entire ranges are blacklisted heavily.

Re: Google broke reCAPTCHA for de-googled Android users

#456
post #313

Earlier quoted context omitted.

How often are your emails being marked as spam, for others? A few years ago it read like there’s a whole science behind avoiding getting flagged. Is this easier now with agents aiding the setup?

I imagine an agent would make a lot of the first time setup from scratch easier, but the fastest reliable way to get up and running is mail-in-a-box or mailcow. Before those were available I built a flurdy style Postfix+Courier+Amavisd+MySQL setup and have been evolving it ever since. Now I'm on Postfix+Dovecot+rspamd+MySQL but I don't think that's for everyone or even the best way to start. The science of not gettin…

Great info, thanks

Re: Google broke reCAPTCHA for de-googled Android users

#458

Earlier quoted context omitted.

Nice, I understand it is similar to ArchiveBox + its web extension. Now to be honest, while it's optimal to archive pages from you browser view I am not sure I want a random web extension to be in everything I see from a security point of view. I would rather have a local proxy doing it. Maybe something like the InternetArchive warcproc [0]. Haven't tried yet. - [0] https://github.com/internetarchive/warcprox

for a short time i had warcprox sitting behind my firefox and auto feeding its output to pywb, it seemed to work but i had connections failing randomly after having warcprox running for more than a few hours~days. not sure if it's an issue with pywb or warcprox but there were some urls missing that i did browse on firefox, and many dynamic pages couldn't be replayed at all.

I am not surprised...

I am unfamiliar with web caching proxies like squid [0] but I am wondering if that might be the most straightforward way to do this.

So use squid and then have a batch job that go through /var/spool/squid every day and update your web archive according to some defined filters.

- [0] https://www.squid-cache.org/

Re: Google broke reCAPTCHA for de-googled Android users

#459

Earlier quoted context omitted.

That's great until it's some essential government, medical, educational, etc. service that you have either no alternative to or no alternative that isn't also using the same thing. I'm already being slowly and incrementally softlocked out of some (fortunately non-essential so far) sites either by cloudflare or other more subtle "anti-bot" networks as time goes on, including some like I've listed above. I can only exp…

> That's great until it's some essential government, medical, educational, etc. service At which point you should contact your attorney general, and work to ensure such efforts face legal challenges at every turn.

Which won’t solve the problem at all.

Re: Google broke reCAPTCHA for de-googled Android users

#460
post #104

I would love to see someone challenge this as an anti-trust violation. Google is using its market power (as the provider of reCAPTCHA) to actively prevent devices that don’t use Google Play Services from competing effectively.

I'm not sure the definition of anti-trust matches what you're saying. Are there any retail android devices for sale without Google Play Services? Also, notably iPhones will be able to still work despite not having Google Play Services.
Post reply on HN