Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

511–520 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#511
post #189

I have a good friend who doesn't own a cell phone. He's a math professor. Every year he keeps living life without a smartphone, I continue to be more impressed. Things like this makes me feel like he might have to eventually give in. https://archive.is is now serving, via Cloudflare, this QR code backed CAPTCHAs. There seems no way to get past them without a smartphone. Sad times. I wonder at what point even basic go…

I don't have one either. No plans to get one, even with this.

No cell phone period or no smart phone? I'm not sure how people manage the former. Do you have a home with a land line? What do you do when you travel?

Re: Google broke reCAPTCHA for de-googled Android users

#512
post #347
post #45

Earlier quoted context omitted.

I don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough". I think it's most likely to be attested by Google remotely; they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone, officially to make better humanity assessment…

> I don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough". Doesn't Play Integrity use hardware attestation, but specifically checking the Google keys? If you use the Play Services on GrapheneOS, you still don't pass Play Integrity because your system is signed by GrapheneOS and not by Google.

No, Play Integrity is a set of numerous features, and the developers decide which one to use, and how to react to what the api reports.

Hardware attestation is one feature, but it's still not used a lot.

The most common feature is the check that your Google account really downloaded the app you're using (and that the app wasn't modified); which requires using a Google account, of course. This is what the "pairip" that's been plaguing the store for a year does (it's being added by a ton of apps because adding it only requires enabling a preference in the Play Console).

Re: Google broke reCAPTCHA for de-googled Android users

#513

Earlier quoted context omitted.

We wouldn't want bots throwing money at us!

I suspect this is a real problem for charities, though. If those bots are using stolen credit cards, the "donations" are going to cost the charities money after they pay extra fees to the credit card processors. Nonprofits are sometimes used to test stolen credit cards before making more profitable fraudulent transactions, so there's a real risk of it costing them money if they get rid of the captcha but don't replac…

Why would they pay extra fees?

Re: Google broke reCAPTCHA for de-googled Android users

#514
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

This should be the way. Have a tiny burner phone for maps and any apps that you absolutely can't use without google(it should be a tiny set of My current de-google project is categorizing all my pictures on my local NAS to create the memories feature (where it shows historic pics on multiple theme axes). You can get really far with just a few hours of work a month to de-google and some off the shelf image embeddings.

The hero project in this category — what one cannot do trivially as an indie dev — is creating a great fresh PoI dataset. This is tough to do on a planetary scale because its a societal cooperation problem.

Re: Google broke reCAPTCHA for de-googled Android users

#515
post #86

Earlier quoted context omitted.

Already happening. The official German identification app, AusweisApp, is designed exclusively for Android and Apple mobile devices

The AusweisApp is Open Source and available on Windows, Linux and even FreeBSD too. You just need some NFC Scanner that works via USB and then you can use it without a mobile device. https://www.ausweisapp.bund.de/open-source-software

This is the way to do it if you're gonna have a digital ID. Thank you Germany for setting a better example than many!

Re: Google broke reCAPTCHA for de-googled Android users

#516
post #513

Earlier quoted context omitted.

I suspect this is a real problem for charities, though. If those bots are using stolen credit cards, the "donations" are going to cost the charities money after they pay extra fees to the credit card processors. Nonprofits are sometimes used to test stolen credit cards before making more profitable fraudulent transactions, so there's a real risk of it costing them money if they get rid of the captcha but don't replac…

Why would they pay extra fees?

Merchants often pay a chargeback fee on top of refunding the main charge. Additionally, merchants with lots of fraud or other chargeback issues are likely to be dropped by payment processors or see their general fees with payment processors get more expensive.

Re: Google broke reCAPTCHA for de-googled Android users

#517
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

Have you tried the Uber webapp?

Re: Google broke reCAPTCHA for de-googled Android users

#518

Earlier quoted context omitted.

Nextcloud, Samba serving SMB isn't really equivalent.

I don't get how Samba is not there yet. We already have everything in the OS, the UI, the mental model, the protocols, how come it's such a terrible experience that we need to re-invent the wheel in web 2.0.. Maybe we need a Jarred Sumner to fix it.

Samba has never been about file sharing over the internet. The project has been about cleanroom-reverse-engineering specific MS technology. To start it was NT4 authentication domains, then printing services, along the way SMBv1 (commonly incorrectly called CIFS btw), then SMBv2 v3.x, and then in 2012 Samba Active Directory.

In no way has it ever been about a functional alternative to something like Nextcloud. It's been about services primarily for LAN functionality, not stuff that should be going over the internet (mostly for security reasons).

So your expectations really don't align with what Samba has ever been about.

Source: I professionally support Samba for businesses.

Re: Google broke reCAPTCHA for de-googled Android users

#519
post #459

Earlier quoted context omitted.

> That's great until it's some essential government, medical, educational, etc. service At which point you should contact your attorney general, and work to ensure such efforts face legal challenges at every turn.

Which won’t solve the problem at all.

No, it won't, and this mechanism should not be used by anyone, but it'd at least ensure that people aren't forced to use it to interact with their government.

Re: Google broke reCAPTCHA for de-googled Android users

#520
post #486

Earlier quoted context omitted.

> They would be a solution if almost all parents used them No, they are a solution for parents who want to use them, and that's all they should be. Their existence demonstrates that it's possible to handle this without regulation, other than the desire of some people to inflict their preferences onto other people's kids.

You haven't tried to use parental controls much have you? They are all terrible. They are insanely difficult to get set up properly and even when you do there are a lot of tradeoffs that come with it.

> even when you do there are a lot of tradeoffs that come with it

Absolutely, but those are nothing compared to the tradeoffs of putting attestation or identity verification (sometimes incorrectly described as "age" verification) on numerous sites and inflicting them on everyone.

Post reply on HN