Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

591–600 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#591
post #586

Earlier quoted context omitted.

> Are you comfortable with anybody being able to ring up the hospital and say "yo, it's majorchord, how are my gonnorhea results?" No, that's why we have safety protocols in place. When you call a doctor they ask you for your birthdate or sometimes also a PIN/password on your account to protect your data. How would that still be considered a breach of privacy?

Alright. I didn't know that. "Just call them" did not sound like it included any kind of authentication procedure. But giving birthdate (available to anyone via a single query in a public database) and ( sometimes?! - what?!) PIN over the phone wouldn't really be considered good enough here. Birthdate is, as I said, public knowledge. And a phone is too insecure a medium for transmitting a password. I'm not super inte…

> And the reality is that "just call them" is not a solution, because such information will simply not be handed out over the phone.

It already is a solution, and has been in widespread use for many decades. I don't think it's going anywhere.

Re: Google broke reCAPTCHA for de-googled Android users

#592

Earlier quoted context omitted.

If you don't mind me asking, what Bank? I've resolved that this phone will be my last googled phone, and my next will be GrapheneOS.

Not OP, but I've been on GrapheneOS for a few years and I have no problem with Chase, CiT or Wealthfront. I mostly use them to check balances and unlock debit cards, but they all login and function fine.

Noted, thank you for the advice.

Re: Google broke reCAPTCHA for de-googled Android users

#593
post #537

Earlier quoted context omitted.

It should be possible with zero knowledge proofs. The problem is that while you might be able to trust the crypto, the government won't trust you to do the crypto entirely by yourself. And this introduces avenues for deanonymisation. Moreover, collusion between the government and the entity making the age check can also theoretically deanonimize. It's a complicated problem. We continue to seek a technological solutio…

> Moreover, collusion between the government and the entity making the age check can also theoretically deanonimize. Hmmm... no? That's not how zero knowledge works.

Not via breaking the ZKP, but via other methods of fingerprinting, which governments are very well positioned to enable.

Re: Google broke reCAPTCHA for de-googled Android users

#594

Earlier quoted context omitted.

Colluded how?

By exchanging and correlating data presumably? For example, anything I send or receive on Discord, I see reflected in my YouTube recommendations shortly after. It's downright egregious at times.

Most likely it's just run of the mill Google analytics/adsense tags in discord. Don't forget that discord is web tech and loads all kinds of JS bundles – including trackers. The best solution is to stop using discord, but the second best solution is to only use the web app version of Discord. When you use the web app, you can install adblock and anti-tracking extensions. The amount of data that Discord sends which gets blocked by these extensions is eye opening.

Re: Google broke reCAPTCHA for de-googled Android users

#595
post #345

My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the…

> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.

No it can't. If it's done in a truly privacy preserving way then someone can also sell a fake age verification service making the whole thing meaningless.

Re: Google broke reCAPTCHA for de-googled Android users

#596
post #563

Earlier quoted context omitted.

I have yet to see a scheme that would robustly preserve privacy and freedom floated by any of the major efforts. I think the onus is on you to present a workable scheme, but even then I'm not going to support the major efforts which at present are malicious.

I keep mentioning it. Read about Privacy Pass, there is a goddamn RFC for it.

Having Privacy in the name doesn't mean it's actually privacy preserving. You can't just ignore attack vectors like collusion between signing entities and websites.

Re: Google broke reCAPTCHA for de-googled Android users

#597
From the screenshot in the article "Troubleshoot reCAPTCHA Mobile Verification":

> To complete the mobile verification, you must use a compatible mobile device.

At first glance, reading this made me wonder: what is exactly a compatible mobile device? But they quickly answered this question just below:

> If verifying on iOS/iPadOS...

> If verifying on Android device with Google Play Services...

OK then, got it! These are the ONLY compatible mobile devices. No de-googled devices are being welcomed here.

Re: Google broke reCAPTCHA for de-googled Android users

#598

Earlier quoted context omitted.

Home Depot at least has a physical presence, which you can go and directly give some much-needed feedback to.

It has a zero percent chance of reaching anyone who can do anything about it. You could try handwriting and posting a letter to their CEO. I think that sometimes works. Probably not very often but there are more than zero CEOs who read those letters.

You can also send an email if you're lazy. In both cases the CEO probably won't read it but a more than minimum wage secretary probably will pass it on to corporate customer support which IME is a lot more useful and the regular support that the company wants you to use.

Re: Google broke reCAPTCHA for de-googled Android users

#599

Earlier quoted context omitted.

Stop visiting sites and using services that use reCAPTCHA. Problem solved. No. Bigger problem created, since there are innumerable government, health care, and educational web sites that use reCAPTCHA. I'm not going to give up reading the test results from my doctor because of some simplistic ideologue decides that it's "problem solved."

> I'm not going to give up reading the test results from my doctor You could just call them.

That misses the point: alternatives will only be available as long as enough people uses them.

Re: Google broke reCAPTCHA for de-googled Android users

#600
post #563

Earlier quoted context omitted.

I keep mentioning it. Read about Privacy Pass, there is a goddamn RFC for it.

Having Privacy in the name doesn't mean it's actually privacy preserving. You can't just ignore attack vectors like collusion between signing entities and websites.

Did you read about how it works? Can you precisely describe an attack that defeats it, or are you just throwing names you've heard without actually knowing how Privacy Pass works? Sounds like the latter to me (yes, I read the RFC).
Post reply on HN