Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

461–470 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#461
Luckily Google reCAPTCHA seems to be dying. Almost everything uses Cloudflare Turnstile, hCaptcha, or some form of a PoW challenge now.

I'd go as far as to say that still having Google reCAPTCHA on your website is a sign of your website being unmaintained. Half of them even have the "reCAPTCHA is changing terms, take action" text on them.

This move will cause the last users to stop using it, and reCAPTCHA will be on the "Killed by Google" list in a year or two.

Re: Google broke reCAPTCHA for de-googled Android users

#462
post #334

Earlier quoted context omitted.

I wish Linus had adopted GPL v3. He had the power to stop this madness from big tech, but he sided with them. It just reveals that he never fully understood the reason for the existence of GPL in the first place.

> He had the power to stop this madness from big tech, but he sided with them. He (Torvalds) had no power to do anything and sold out. Even if he did, big tech would just go and use BSD. For over a decade both Torvalds, and Stallman sold everyone out. They don't make their money directly from "free software" or "open source" in the first place. Stallman was right in that he knew digital surveillance was going to happ…

What do you define as selling out? Having a different perspective from your own? There are many legitimate reasons for why someone can believe the opposing view points. Devolving into us vs them rhetoric is not conducive to a reasonable conversation.

Re: Google broke reCAPTCHA for de-googled Android users

#463
post #85

Earlier quoted context omitted.

I wanted to give money to charity and they have whole form protected by recaptcha. So I would have to allow all my personal information and amount donated sent to google (and agree with google terms for data processing). I have contacted them but they did not understand why this is problem they just wanted to protect themself against bots. IMHO unless those things are not disallowed by antitrust laws we have lost.

We wouldn't want bots throwing money at us!

I suspect this is a real problem for charities, though. If those bots are using stolen credit cards, the "donations" are going to cost the charities money after they pay extra fees to the credit card processors. Nonprofits are sometimes used to test stolen credit cards before making more profitable fraudulent transactions, so there's a real risk of it costing them money if they get rid of the captcha but don't replace it with something sufficiently high quality, even after accounting for the occasional lost donation.

Re: Google broke reCAPTCHA for de-googled Android users

#464

Earlier quoted context omitted.

That key will get leaked. A key that has to go into every phone, even if done at the manufacturer and onto the TPM chip, will get out. Also even if it doesn't get leaked directly, the security of TPM chips is not absolute. Secrets from them can theoretically be extracted given an attacker with sufficient means and motivation. Normally nothing that's on a typical TPM chip would warrant a project of that magnitude, but…

> That key will get leaked. Maybe? But biometric passports, chip-and-pin payment cards and SIM cards seem to do reasonably well. And Apple can always push out a mandatory software update that rotates the key, if they need to. > You could swap out the actual phone camera hardware and sensors for a custom board that feeds the entire phone camera data of your choosing and it would be none-the-wiser. Apple's 'TrueDepth'…

> Apple's 'TrueDepth' cameras are serialised and paired with the rest of the device. The touch ID sensors were before that too.

That prevents trying to swap the module, but doesn't prevent swapping out the sensor on the module itself.

Re: Google broke reCAPTCHA for de-googled Android users

#465
post #313

Earlier quoted context omitted.

How often are your emails being marked as spam, for others? A few years ago it read like there’s a whole science behind avoiding getting flagged. Is this easier now with agents aiding the setup?

I imagine an agent would make a lot of the first time setup from scratch easier, but the fastest reliable way to get up and running is mail-in-a-box or mailcow. Before those were available I built a flurdy style Postfix+Courier+Amavisd+MySQL setup and have been evolving it ever since. Now I'm on Postfix+Dovecot+rspamd+MySQL but I don't think that's for everyone or even the best way to start. The science of not gettin…

For the people who's mail service blocks you and they cannot or will not change their mail provider, what is your solution?

Re: Google broke reCAPTCHA for de-googled Android users

#467
post #344

> People running de-Googled phones chose those setups because they read the data practices, understood what Play Services phones home about, and decided they didn’t consent. This is wrong. Many (most?) users of alternative Android OSes do use a variant of the Play Services (be it sandboxed Play Services like on GrapheneOS, or an open source, reverse engineered implementation like microG that phones home just the same…

There is a fundamental tension here though - suppose DMA or something requires that online providers recognise reCAPTCHAs from non-Google-attested OS builds. What OSs can they safely trust? Only ones that are difficult for fraudsters to use to generate bogus traffic. Whether or not those builds come from Google, they are inherently gonna be pretty constrained OSs. It's not gonna let you spoof your location or simulat…

Arguably anyone else who can provide a similar level of trustworthy authentication that they are not a bot can work with Google to get support. Fundamentally this is a trust based problem and only OS providers are even capable of building such systems. There are very few of those out there. The key is that the systems need to be locked down to prevent automation of input and that automatically disqualifies most android alternatives that the community likes. It's clear that Apple offers this capability though. I can imagine a more locked down version of Windows also providing this in the future.

Re: Google broke reCAPTCHA for de-googled Android users

#468

Earlier quoted context omitted.

Sometimes, people just do dumb choices, there is nothing to understand except plain lazyness, there is better captchas, free, non-invasive, more secure, GDPR compliant and so-on that are also not covered by captcha-solving providers, so what's the positive argument about reCaptcha?

A very strong brand?

You really think it's the reason? I've worked with many developers, and they use reCaptcha just because they are used to it and did it in the past, I doubt customers love the "reCaptcha branding", to the contrary, nicer captchas (or even invisible ones, even better) improve retention.

Re: Google broke reCAPTCHA for de-googled Android users

#469

Earlier quoted context omitted.

A very strong brand?

You really think it's the reason? I've worked with many developers, and they use reCaptcha just because they are used to it and did it in the past, I doubt customers love the "reCaptcha branding", to the contrary, nicer captchas (or even invisible ones, even better) improve retention.

"Because I'm used to it" is what a strong brand is.

Re: Google broke reCAPTCHA for de-googled Android users

#470
post #386

Earlier quoted context omitted.

Not the person you replied to, and it's impossible to know with certainty how often you're in someone else's spam, but very rarely. I had an issue with yahoo a couple of years ago that's all. The "it read like there's a whole science" is sadly a trope mostly repeated by people who have never tried because it gets upvotes on Reedit. There are some steps you have to take, but not many, and systems like Mox mailserver o…

You got me really interested here, I ran my own mailserver years ago and eventually just gave it up. I am getting rid of Google Workspace and have been planning a migration to Proton for two domains. But this sounds like a fun project. Any advice? I am going to check out Mox and Stalwart. What providers are good hosting candidates, I have a website on DO, but from my understanding their entire ranges are blacklisted…

If I remember rightly DO have some restrictions like port 25 on ipv6 outbound being blocked.

I can't speak for all of them but I use mythic beasts in the UK for one mail server (they are a very knowledgeable old school host) and it has been good. I also have dedicated with OVH which is fine, and a couple small scale (eg simplelogin, a notification server) with IONOS but they only deliver to me so I can't say how reliably they deliver elsewhere.

Mox is great but I think it's still alpha. I've been using it for 2 years in production for a small traffic domain. The other I use Exim (with mythic beast's Sympl that sets it up) but it's a little more hands on at the beginning

Post reply on HN