Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

471–480 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#472
post #319

Earlier quoted context omitted.

Shouldn't that be illegal under GDPR?

There are massive exemptions for the prevention and detection of crime And https://gdpr.eu/recital-49-network-and-information-security-... : > Recital 49 - Network and Information Security as Overriding Legitimate Interest > The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information s…

What crime are you preventing or detecting by verifying you're human?

Re: Google broke reCAPTCHA for de-googled Android users

#473
post #292
post #104

I would love to see someone challenge this as an anti-trust violation. Google is using its market power (as the provider of reCAPTCHA) to actively prevent devices that don’t use Google Play Services from competing effectively.

They're only doing that because the EU currently doesn't want to antagonize US any more with their tech fines. Noticed how there hasn't been any as of recently?

[deleted]

Re: Google broke reCAPTCHA for de-googled Android users

#474
post #344

> People running de-Googled phones chose those setups because they read the data practices, understood what Play Services phones home about, and decided they didn’t consent. This is wrong. Many (most?) users of alternative Android OSes do use a variant of the Play Services (be it sandboxed Play Services like on GrapheneOS, or an open source, reverse engineered implementation like microG that phones home just the same…

There is a fundamental tension here though - suppose DMA or something requires that online providers recognise reCAPTCHAs from non-Google-attested OS builds. What OSs can they safely trust? Only ones that are difficult for fraudsters to use to generate bogus traffic. Whether or not those builds come from Google, they are inherently gonna be pretty constrained OSs. It's not gonna let you spoof your location or simulat…

Wanting to load a webpage anonymously is not something that makes one a “fraudster”.

Re: Google broke reCAPTCHA for de-googled Android users

#475
post #344

> People running de-Googled phones chose those setups because they read the data practices, understood what Play Services phones home about, and decided they didn’t consent. This is wrong. Many (most?) users of alternative Android OSes do use a variant of the Play Services (be it sandboxed Play Services like on GrapheneOS, or an open source, reverse engineered implementation like microG that phones home just the same…

There is a fundamental tension here though - suppose DMA or something requires that online providers recognise reCAPTCHAs from non-Google-attested OS builds. What OSs can they safely trust? Only ones that are difficult for fraudsters to use to generate bogus traffic. Whether or not those builds come from Google, they are inherently gonna be pretty constrained OSs. It's not gonna let you spoof your location or simulat…

> What OSs can they safely trust?

None. The first rule of network security is you can't trust the client.

All attempts at remote attestation of consumer devices are someone wanting to break this rule. It's always a mistake; the OS being on the blessed list raises the difficulty level for fraud a little, but serious fraudsters have already perfected workarounds.

Re: Google broke reCAPTCHA for de-googled Android users

#476
post #415

Earlier quoted context omitted.

> I'm not going to give up reading the test results from my doctor You could just call them.

Fairly sure that would be considered a breach of patient confidentiality where I live, at least.

Sorry to hear that. What did people do before computers then?

Re: Google broke reCAPTCHA for de-googled Android users

#477
I worked at Google. I know there are tons and tons of great and well meaning people working there. This is the kind of thing that would make me crazy.

People there be like, “but I’m not evil! I’ll never do anything bad with all of this incredible power!”

But if you create a nuclear bomb, someone unsavory is going to wrest control of that power from your stupid little painted fingernails and destroy the rest of us with it.

How about, don’t make an effing privacy nuclear bomb if you don’t want to contribute to making the world more evil?

Re: Google broke reCAPTCHA for de-googled Android users

#478
post #86
post #58

Earlier quoted context omitted.

It's all fun until you can't get paid because some fintech app doesn't work. That's why we need regulations. I don't see politicians ever going against an advertising company when they're customers.

Already happening. The official German identification app, AusweisApp, is designed exclusively for Android and Apple mobile devices

The AusweisApp is Open Source and available on Windows, Linux and even FreeBSD too. You just need some NFC Scanner that works via USB and then you can use it without a mobile device. https://www.ausweisapp.bund.de/open-source-software

Re: Google broke reCAPTCHA for de-googled Android users

#479
post #470

Earlier quoted context omitted.

You got me really interested here, I ran my own mailserver years ago and eventually just gave it up. I am getting rid of Google Workspace and have been planning a migration to Proton for two domains. But this sounds like a fun project. Any advice? I am going to check out Mox and Stalwart. What providers are good hosting candidates, I have a website on DO, but from my understanding their entire ranges are blacklisted…

If I remember rightly DO have some restrictions like port 25 on ipv6 outbound being blocked. I can't speak for all of them but I use mythic beasts in the UK for one mail server (they are a very knowledgeable old school host) and it has been good. I also have dedicated with OVH which is fine, and a couple small scale (eg simplelogin, a notification server) with IONOS but they only deliver to me so I can't say how reli…

Excellent thanks

Re: Google broke reCAPTCHA for de-googled Android users

#480
post #367
post #345

Earlier quoted context omitted.

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

Look at Apple’s PAT: the website knows the service that did the attestation, but not the user. The service knows the user, but not the website. If you controlled both you can link the user, but otherwise you can’t.
Post reply on HN