Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

221–230 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#221

Earlier quoted context omitted.

An easy first step ahead of a full ban would be insisting that hardware attestation never be used as a gate to access government services. Most other things I can vote with my feet, but viewing my tax returns or renewing my passport are things that can only happen in one place.

This is really the most important thing for me. I don’t want to be obligated by law to use some identity or attestation service tied to big tech. I might be ok with my bank handling it because they already require ultimate trust, but not if they simply defer to big tech or implement infrastructure on foreign ccTLDs (id.me, verified.me, etc.). I’m Canadian and watching our government sell our souls to American tech co…

Yes, Canadian here also and I feel the same. I'm pretty heavily Googled these days (gmail, gphotos, Pixel 10) and I work for a US tech company, so maybe I'm kidding myself that it matters much for me personally, but I'd be pretty sad if I ever found myself unable to access any level of government service because I didn't have a Google or Apple smartphone that I could point at a QR code on the screen.

Re: Google broke reCAPTCHA for de-googled Android users

#222
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

What's the best alternative for Google drive? I also went this route but Samba is a bit annoying sometimes

Nextcloud, Samba serving SMB isn't really equivalent.

Re: Google broke reCAPTCHA for de-googled Android users

#223
post #168

Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?

I run into https://www.hcaptcha.com/ and https://friendlycaptcha.com/ from time to time as a user without complaint. Can't speak to the latter but I've used the former a bit and it does the job.

Any chance for something 100% self-hostable? hcaptcha and friendlycaptcha last I checked require interfacing with their services.

Re: Google broke reCAPTCHA for de-googled Android users

#224
post #214

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…

You can still use the audio captcha, but I’m not sure how long that’ll be around.

Google will incur serious lawsuits if they remove that accessibility aspect.

Re: Google broke reCAPTCHA for de-googled Android users

#226
post #24

Time for some lawfare!

The Government reviewed the Google situation on behalf of you, and on behalf of the Government, and said “data, so piss off”: https://abcnews.com/Technology/google-hit-antitrust-lawsuit-... https://macdailynews.com/2026/02/04/u-s-files-appeal-in-goog...

If the masses can somehow point the absolute loose-cannon that is the current President at Google, things might actually change.

Re: Google broke reCAPTCHA for de-googled Android users

#227

Earlier quoted context omitted.

With the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.

I have been unable to give my money to Home Depot, REI and a growing list of online retailers because they use Akamai EdgeSuite, which just assumes I am a bot and 403s on protected API calls. This happens consistently on any IP and any browser on my Linux desktop/laptop.

Home Depot at least has a physical presence, which you can go and directly give some much-needed feedback to.

Re: Google broke reCAPTCHA for de-googled Android users

#228

Earlier quoted context omitted.

They get blocked by Recaptcha, I think. I’m not talking about the network itself but the servers on the other end. I guess my point is that while Google is definitely malicious, I don’t think every site using recaptcha is and if we expect them not to use that tool there should probably be an alternative.

> They get blocked by Recaptcha, I think. I think SV was asking what onion services, which can't really use recaptcha, do to prevent the DDoS storm. And I would imagine the answer is obscurity, since the dark web isn't nearly as well-mapped as the public web. That and some Anubis or other PoW would probably go far.

Proof of work I get, but isn’t that like step2?

If I’m hosting at some IP, I still need Anubis or something to serve up the challenge, so doesn’t that become the attack point?

Re: Google broke reCAPTCHA for de-googled Android users

#229

Earlier quoted context omitted.

Yes, I have even seen mobile android games that include notices about a BrightData SDK or HolaVPN etc. where their idle bandwidth is resold.

Does the app function as a proxy? I always assumed that wasn’t possible.

Why wouldn't it be possible? As long as background network access is allowed (the default).
Post reply on HN