Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

491–500 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#491

Earlier quoted context omitted.

In August 2019, Trump tweeted that Google had “manipulated” millions of votes toward Clinton in 2016 and said the company “should be sued.” Turns out that Presidents, once elected, largely do what Continuity of Government, and business interests, ask for.

Trump has been the least normal of them, and the increasing distrust and suspicion towards Big Tech is largely bipartisan at this point.

> Trump has been the least normal of them

In some ways, yes.

In other, major ways: a spade is a spade.

Re: Google broke reCAPTCHA for de-googled Android users

#492
post #345

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

Doesn't matter if it is privacy preserving, it is still an evil thing to do

Re: Google broke reCAPTCHA for de-googled Android users

#493

Earlier quoted context omitted.

In August 2019, Trump tweeted that Google had “manipulated” millions of votes toward Clinton in 2016 and said the company “should be sued.” Turns out that Presidents, once elected, largely do what Continuity of Government, and business interests, ask for.

Trump has been the least normal of them, and the increasing distrust and suspicion towards Big Tech is largely bipartisan at this point.

> suspicion towards Big Tech is largely bipartisan at this point.

Largely a bipartisan talking point…not many true Wyden’s out there.

Re: Google broke reCAPTCHA for de-googled Android users

#494

Earlier quoted context omitted.

There is a fundamental tension here though - suppose DMA or something requires that online providers recognise reCAPTCHAs from non-Google-attested OS builds. What OSs can they safely trust? Only ones that are difficult for fraudsters to use to generate bogus traffic. Whether or not those builds come from Google, they are inherently gonna be pretty constrained OSs. It's not gonna let you spoof your location or simulat…

Arguably anyone else who can provide a similar level of trustworthy authentication that they are not a bot can work with Google to get support. Fundamentally this is a trust based problem and only OS providers are even capable of building such systems. There are very few of those out there. The key is that the systems need to be locked down to prevent automation of input and that automatically disqualifies most andro…

Yes that is what i mean, anyone can do it technically, but they are gonna have to build a slightly crappy OS in order to do it.

But still, better multiple slightly crappy OSs instead of just one (plus Apple).

Re: Google broke reCAPTCHA for de-googled Android users

#495
post #375

Earlier quoted context omitted.

Parental controls on device are a better solution that work today and don't carry a risk of data breach.

They would be a solution if almost all parents used them, but parents don't want to socially isolate their kids since a lot of "social" activity is now on social media. It's kind of a prisoner's dilemma. There's not necessarily wrong. Despite the vapid and damaging nature of most popular online media, isolating a child from it might have even worse social consequences when their real-life peer groups discover that th…

How about we just ban entirely the harmful social media that we would need to attach all our IDs to our internet activity in order to protect the children? Very strange that that's not part of the discussion!

Re: Google broke reCAPTCHA for de-googled Android users

#496
post #344

> People running de-Googled phones chose those setups because they read the data practices, understood what Play Services phones home about, and decided they didn’t consent. This is wrong. Many (most?) users of alternative Android OSes do use a variant of the Play Services (be it sandboxed Play Services like on GrapheneOS, or an open source, reverse engineered implementation like microG that phones home just the same…

Exactly. Imagine them blocking captchas on iphone or windows

IIUC, They are blocking it on windows, unless you have an android or iOS device you can use to complete the "captcha"

Re: Google broke reCAPTCHA for de-googled Android users

#497

Earlier quoted context omitted.

Syncthing is very nice.

Is not the same though. It requires downloading the entire shared folder. That doesn't work when I have 100+GB of files and I want to share it with my phone

https://docs.syncthing.net/users/ignoring.html

Re: Google broke reCAPTCHA for de-googled Android users

#498

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

worth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on (just realized emacs bindings work in comments, nice, no ctrl-x t…

> (just realized emacs bindings work in comments, nice, no ctrl-x tho)

Are you using macOS? If so, those keybindings work everywhere.

As far as I can tell, Hacker News doesn't impose any custom keybindings (the client-side scripting on this site[0] is very simple).

[0]: https://news.ycombinator.com/hn.js

Re: Google broke reCAPTCHA for de-googled Android users

#499

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…

I thought archive.is were the ones squabbling with Cloudflare (extreme simplification)

Their squabble was to claim that Cloudflare wouldn’t let them collect identifying information about the original requestor. No doubt they’re thrilled by this change’s identity exposure.

Re: Google broke reCAPTCHA for de-googled Android users

#500
post #73

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least: - pretended that it wasn't all about invading peoples' privacy. - done a good ol' fashioned "but Apple does it" - pretended to be standards-oriented - advertised it as something completely transparent to the end-user Seems like that would've caused a lot less backlash while still achiev…

It doesn't fundamentally solve anything. You want to be able to identify a specific person or at least a relatively expensive device so that if you ban them they stay banned.

This is the exact method used to secure iMessage against spam: secure attestation and ‘console’ bans of devices (reversible by iirc phoning support, indicating who you purchased the used device from, and providing an ID). But Google is trying to pull a Windows 11 “TPM or die” conversion on the public Internet via Recaptcha. Welcome to the attestation wars, unwitting websites :)
Post reply on HN