Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

521–530 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#521
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

What do you use for calendar and tasks hosting?

I'm on a similar journey and I use Radicale.

Re: Google broke reCAPTCHA for de-googled Android users

#522

Earlier quoted context omitted.

worth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on (just realized emacs bindings work in comments, nice, no ctrl-x t…

> (just realized emacs bindings work in comments, nice, no ctrl-x tho) Are you using macOS? If so, those keybindings work everywhere. As far as I can tell, Hacker News doesn't impose any custom keybindings (the client-side scripting on this site[0] is very simple). [0]: https://news.ycombinator.com/hn.js

Emacs bindings also work on Linux in GTK apps, if you enable them:

  gsettings set org.gnome.desktop.interface gtk-key-theme "Emacs"
If you make Qt follow GTK settings, they also work in many Qt apps, too, but in a more limited way.

Re: Google broke reCAPTCHA for de-googled Android users

#523
post #345

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

As far as I know no currently proposed age verification method does this in practice.

The only way to implement truly privacy preserving age verification is through zero knowledge proofs (or blind signatures) but what that would allow is undetectable token forging.

Re: Google broke reCAPTCHA for de-googled Android users

#524

Earlier quoted context omitted.

The sites that require you to log in are precisely the same ones that are crawling with bots. The personal internet or "small web" is, and still will be, full of real content. There are also lots of bot websites that are trying to be small web, but since it's an actual social network and not a giant pool everyone pours stuff into, they don't get traction. If you do find a website that seems to be human but links to a…

It's less about those sites than it is about government services, banking, healthcare, employment, etc

Your online banking will be overrun with bots? Your healthcare will be overrun with bots?

What does that even mean?

Re: Google broke reCAPTCHA for de-googled Android users

#525
post #367

Earlier quoted context omitted.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

The trick is to define "privacy-preserving age verification" in an extremely narrow way that ignores any other privacy concerns. For example, imagine you put the same private key into the 'secure element' of every single iphone. You use code signing so that key is only unlocked when the phone is running unmodified iOS with all security updates. You use encryption and remote attestation for the front-facing camera and…

OR:

The website sends a request for age verification.

The app[1] on the user's device[2] forwards that request to the chip on the user's ID card. The user authorizes themselves with their 6 digit PIN stored on the card.

The chip produces a signed reply containing the following payload fields: `issuing_country:string` and `over_18:bool`

[1] https://github.com/Governikus/AusweisApp

[2] iPhone, Android, Windows, MacOS, Linux or FreeBSD

Re: Google broke reCAPTCHA for de-googled Android users

#526
post #340

Earlier quoted context omitted.

Can you run Graphene on non Pixel phones?

You can use Lineage [/with microG]

This. For privacy, it is much better to avoid Google Play services (which are the only supported solution for push notifications in GrapheneOS).

Re: Google broke reCAPTCHA for de-googled Android users

#527
post #415

Earlier quoted context omitted.

Fairly sure that would be considered a breach of patient confidentiality where I live, at least.

Sorry to hear that. What did people do before computers then?

Not sure how that's relevant. There are computers now. Regulations change with the times. Green lasers weren't controlled in the 1700:s either.

Are you comfortable with anybody being able to ring up the hospital and say "yo, it's majorchord, how are my gonnorhea results?"

Re: Google broke reCAPTCHA for de-googled Android users

#528
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

This should be the way. Have a tiny burner phone for maps and any apps that you absolutely can't use without google(it should be a tiny set of My current de-google project is categorizing all my pictures on my local NAS to create the memories feature (where it shows historic pics on multiple theme axes). You can get really far with just a few hours of work a month to de-google and some off the shelf image embeddings.…

The problem with this is gmaps. There is no alternative to it and by the nature of it knowing your location it removes anonymity. I would buy, or even pay a monthly fee, for something that is 75% as good as gmaps but respects your privacy but there is nothing out there I have found.

Re: Google broke reCAPTCHA for de-googled Android users

#529
post #106

I've kept a spare cheap android for too long and recently went with Graphene instead. I have one Google profile and only use it for Uber, work's Google Chat and maps. One bank refused to work (even with Google services) so I moved bank. I've moved most of my mobile use to self hosted (freshrss full text, password manager, calendar, tasks) with no direct internet connection. It's a bit irritating but I'm glad I starte…

What's the best alternative for Google drive? I also went this route but Samba is a bit annoying sometimes

Proton Drive works well and is from a company that supports privacy but does require a paid subscription.

Re: Google broke reCAPTCHA for de-googled Android users

#530
post #527

Earlier quoted context omitted.

Sorry to hear that. What did people do before computers then?

Not sure how that's relevant. There are computers now . Regulations change with the times. Green lasers weren't controlled in the 1700:s either. Are you comfortable with anybody being able to ring up the hospital and say "yo, it's majorchord, how are my gonnorhea results?"

> Are you comfortable with anybody being able to ring up the hospital and say "yo, it's majorchord, how are my gonnorhea results?"

No, that's why we have safety protocols in place. When you call a doctor they ask you for your birthdate or sometimes also a PIN/password on your account to protect your data.

How would that still be considered a breach of privacy?

Post reply on HN