Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

421–430 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#421

Earlier quoted context omitted.

For some reason, I'm softlocked from booking tickets from Deutsche Bahn. The website errors out with a cryptic "Your browser's behavior resembles that of a bot." message with no option to try again or pass a captcha or whatever. The website itself described several possible solutions but none helped (I tried using different computers, different internet connections, even a phone connected to internet using a SIM from…

Same problem but with French equivalent SNCF (sncf-connect.com). I just checked and can confirm nothing has changed. You cannot use up-to-date Firefox on Linux to access the main booking site for French rail tickets. Access is temporarily restricted We detected unusual activity from your device or network. Reasons may include: -Rapid taps or clicks -JavaScript disabled or not working -Automated (bot) activity on your…

Does it work if you spoof the user agent?

> -Use of developer or inspection tools

Gotta love it.

Re: Google broke reCAPTCHA for de-googled Android users

#422

Earlier quoted context omitted.

How about consumers paying a little extra for their device? The way it's going, add sponsored big tech is dieing because click fraud detection is becoming too expensive. Either we give up privacy and track every user, or we let bots have at it, stop targeting ads to users and bill advertisers on bandwidth.

if you think consumers will pay more for the vague notion of privacy i have beachfront property in kansas to sell you. most normies either don't care ("I have nothing to hide ... do you?") or gave up already ("china / the government / big tech / all of the above already have all my data, why would I care if it's a bit more? what are they even going to do with it?" (sometimes, even "i like having relavent ads!")). at…

What's wrong with having something to hide? I do.

Re: Google broke reCAPTCHA for de-googled Android users

#423

Earlier quoted context omitted.

Same problem but with French equivalent SNCF (sncf-connect.com). I just checked and can confirm nothing has changed. You cannot use up-to-date Firefox on Linux to access the main booking site for French rail tickets. Access is temporarily restricted We detected unusual activity from your device or network. Reasons may include: -Rapid taps or clicks -JavaScript disabled or not working -Automated (bot) activity on your…

Does it work if you spoof the user agent? > -Use of developer or inspection tools Gotta love it.

Developer tools are easily detected by looking for the viewport to resize a certain amount.

Re: Google broke reCAPTCHA for de-googled Android users

#424
post #367

Earlier quoted context omitted.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

All states/governments have basic records on their citizens and residents, including at least a name, dob, address, etc, at least for a passport, driver's license, if not an actual id card. Let's assume this is acceptable. Then it's technically possible (and really not that difficult) for states to provide a service that issues zero-knowledge proofs of facts like "age > X".

> Let's assume this is acceptable.

(partly off-topic rant) One can argue this is a false premise fallacy. For most of the time states did not have this information about their citizens and the world progressed quite nicely. The only argument to know stuff about citizens that don't drive (increasing numbers) nor travel abroad (different problem altogether) is to tax them?

One of the foundational differences between humans and cattle was you cannot brand (https://en.wikipedia.org/wiki/Livestock_branding) humans. Not physically, because we do it digitally and I see a slippery slope.

Re: Google broke reCAPTCHA for de-googled Android users

#425

Earlier quoted context omitted.

I think you can just search 'buy google account' - it isn't illegal.

Sure but how do I know that the person I'm buying from legitimately owns the account? Won't scam me? Or try to con me out of my existing account? I'm just saying not everyone is as relaxed about that sort of thing.

Markets are regulated by reviews, seller history and so-on, the same as legal markets and it's generally smooth.

Re: Google broke reCAPTCHA for de-googled Android users

#426
post #367
post #345

Earlier quoted context omitted.

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

Blind signatures would work, with a bit of effort.

Re: Google broke reCAPTCHA for de-googled Android users

#427

OK, so what are the alternatives, what can developers use instead?

It feels ultra sad that "developers" think they need to use reCaptcha? What is this lazyness, it's not even good on top of that at what it does, recaptcha cost less than $1/1000 to solve automatically, it's also slow, crappy, bad UI.

Even competent people got completely brainwashed, crazy.

Re: Google broke reCAPTCHA for de-googled Android users

#428
post #346

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved.

> Stop visiting sites and using services that use reCAPTCHA. Problem solved. Not solved at all: 99.999% of users don't give a damn and use a Google-signed Android. My opinion is that because they don't give a damn does NOT mean regulations should not protect them. What Google is doing here is anticompetitive and they should be fined (antitrust and all that).

I don't see the correlation with Google-signed android actually, people really want to have this friction when they visit a website? Like having to get your phone from another room, use camera and all that to access a website? This is so anti-pattern and is also disrespectful toward consumers, any webmaster participating into this imo should rethink his career and morality.

Re: Google broke reCAPTCHA for de-googled Android users

#429
post #168

Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?

I run into https://www.hcaptcha.com/ and https://friendlycaptcha.com/ from time to time as a user without complaint. Can't speak to the latter but I've used the former a bit and it does the job.

hCaptcha is horrible. I think that a PoW captcha would be effective to make spammers just mine Monero instead.

Re: Google broke reCAPTCHA for de-googled Android users

#430

Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?

hcaptcha is pretty popular these days. It uses a very wide variety of traditional visual puzzles.

hCaptcha is horrible. I think that a PoW captcha would be effective to make spammers just mine Monero instead.
Post reply on HN