Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

541–550 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#541

Earlier quoted context omitted.

They would be a solution if almost all parents used them, but parents don't want to socially isolate their kids since a lot of "social" activity is now on social media. It's kind of a prisoner's dilemma. There's not necessarily wrong. Despite the vapid and damaging nature of most popular online media, isolating a child from it might have even worse social consequences when their real-life peer groups discover that th…

I should not have to surrender my anonymity because parents are too lazy to setup parental controls.

And it's possible to do age verification in a privacy-preserving manner. I'm tired of repeating it, people should get informed before they complain.

We could totally discuss whether or not privacy-preserving age verification is a good thing. But we can't, because most people can't be arsed to read about what age verification implies, and complain about something that is fundamentally wrong (i.e. that they would have to surrender their anonymity).

Re: Google broke reCAPTCHA for de-googled Android users

#542

Earlier quoted context omitted.

They would be a solution if almost all parents used them, but parents don't want to socially isolate their kids since a lot of "social" activity is now on social media. It's kind of a prisoner's dilemma. There's not necessarily wrong. Despite the vapid and damaging nature of most popular online media, isolating a child from it might have even worse social consequences when their real-life peer groups discover that th…

How about we just ban entirely the harmful social media that we would need to attach all our IDs to our internet activity in order to protect the children? Very strange that that's not part of the discussion!

Because privacy-preserving age verification is less extreme than banning them entirely. It should be strictly easier to get it accepted.

Except that people can't read for 5min and understand that age verification can be done in a privacy preserving manner.

Re: Google broke reCAPTCHA for de-googled Android users

#543
post #540

Earlier quoted context omitted.

> even when you do there are a lot of tradeoffs that come with it Absolutely, but those are nothing compared to the tradeoffs of putting attestation or identity verification (sometimes incorrectly described as "age" verification) on numerous sites and inflicting them on everyone.

> but those are nothing compared to the tradeoffs And my whole point is that it's possible to do age verification in a privacy-preserving manner, and before complaining about the tradeoffs, you should get informed about what they are.

I'm well aware of those possibilities. The two biggest problems with them are that 1) they still apply to everyone, rather than only to those who opt into them and 2) governments and companies are in practice going to push for the versions that identify people and provide more information.

If you make it possible for governments to decide what content is "limited to adults", they can and will abuse that capability. "Porn" is the battle cry, to make it uncomfortable to argue against; often, other information the government wants to restrict becomes a target. The only way to prevent that is to deny the capability in the first place.

Re: Google broke reCAPTCHA for de-googled Android users

#544
post #367

Earlier quoted context omitted.

Really, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site

The trick is to define "privacy-preserving age verification" in an extremely narrow way that ignores any other privacy concerns. For example, imagine you put the same private key into the 'secure element' of every single iphone. You use code signing so that key is only unlocked when the phone is running unmodified iOS with all security updates. You use encryption and remote attestation for the front-facing camera and…

Wait what? All the time you spent writing that nonsense could have been invested in reading about how it actually works.

Re: Google broke reCAPTCHA for de-googled Android users

#545
post #539
post #375

Earlier quoted context omitted.

Parental controls on device are a better solution that work today and don't carry a risk of data breach.

Zero knowledge proofs don't carry a risk of data breach, because they are zero knowledge.

Your privacy has to be violated in order to receive the easily trackable ZKP tokens.

Re: Google broke reCAPTCHA for de-googled Android users

#546

Earlier quoted context omitted.

The trick is to define "privacy-preserving age verification" in an extremely narrow way that ignores any other privacy concerns. For example, imagine you put the same private key into the 'secure element' of every single iphone. You use code signing so that key is only unlocked when the phone is running unmodified iOS with all security updates. You use encryption and remote attestation for the front-facing camera and…

That key will get leaked. A key that has to go into every phone, even if done at the manufacturer and onto the TPM chip, will get out. Also even if it doesn't get leaked directly, the security of TPM chips is not absolute. Secrets from them can theoretically be extracted given an attacker with sufficient means and motivation. Normally nothing that's on a typical TPM chip would warrant a project of that magnitude, but…

There is no reason to talk about that system: it's nonsense. It's like inventing a bad encryption protocol and discuss about why it is bad.

Better learn about the good one, but I guess it's harder than making up nonsense.

Re: Google broke reCAPTCHA for de-googled Android users

#547

Earlier quoted context omitted.

The trick is to define "privacy-preserving age verification" in an extremely narrow way that ignores any other privacy concerns. For example, imagine you put the same private key into the 'secure element' of every single iphone. You use code signing so that key is only unlocked when the phone is running unmodified iOS with all security updates. You use encryption and remote attestation for the front-facing camera and…

All so kids can't access PornHub? Jesus Christ. 14 year old me ran into porn on the internet all the time. It didn't turn me into a serial killer. Meanwhile we let kids have exposure to algorithms that pervert their sense of self worth, get them addicted to dopamine and gambling, and make them feel inferior to their peers. We have the wrong priorities as a society. And this bullshit is going to turn us into a complet…

Dude, a big reason for age verification is to prevent kids from accessing those "algorithms" you describe.

They will always be able to access porn, e.g. over torrent. It will just be a little less accessible, and maybe it won't hurt.

Re: Google broke reCAPTCHA for de-googled Android users

#548
post #539

Earlier quoted context omitted.

Zero knowledge proofs don't carry a risk of data breach, because they are zero knowledge.

Your privacy has to be violated in order to receive the easily trackable ZKP tokens.

> Your privacy has to be violated

No.

> the easily trackable ZKP tokens

If it's easily trackable, it's not ZK.

Re: Google broke reCAPTCHA for de-googled Android users

#549

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare) , forcing website visitors to KYC? Are you guys insane!? the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f https://ibb.co/X9Q6Y84 By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstor…

Seriously? I didn't realize this was already happening. FWIW I still got the old captcha testing that site, and I often get flagged and blocked, though it's possible you're doing better.

If you reload the page it'll give you a non QR code captcha to do. Hopefully it stays that way or attestation captchas are removed entirely.

Re: Google broke reCAPTCHA for de-googled Android users

#550

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.

So basically Google can now ban your device from being able to access a huge portion of the internet, in addition to nuking any online presence connected to them.

You could wake up one day and find your device blacklisted from the internet, with no chance of ever reaching customer support. What a lovely future

Post reply on HN