Live data from Hacker News

Google broke reCAPTCHA for de-googled Android users

reclaimthenet.org

601–610 of 618 posts

Re: Google broke reCAPTCHA for de-googled Android users

#601
post #537

Earlier quoted context omitted.

> Moreover, collusion between the government and the entity making the age check can also theoretically deanonimize. Hmmm... no? That's not how zero knowledge works.

Not via breaking the ZKP, but via other methods of fingerprinting, which governments are very well positioned to enable.

I feel like it becomes bad faith at some point. With a sufficiently advanced attack, you can be personally identified today. ZKP for age verification does not make this worse, does it?

It's a bit like saying "no but Signal is not really encrypted, because the government can extract some metadata by looking at the network around the server".

Re: Google broke reCAPTCHA for de-googled Android users

#602
post #576

Earlier quoted context omitted.

I don't have one either. No plans to get one, even with this.

I envy you. Before I degoogled my life, I tried going all in to no smart phone. It didn't last very long. I still would like to get there, but considering how difficult and slow it was just to degoogle, I anticipate that it may be a long time before I can operate without a smart phone.

The main thing that makes me think about getting a smartphone is navigation. But I never lost the skill of "looking up/writing down directions before you go" so it's not too bad.

(My phone is technically Android, but really old, not a touchscreen, you can't install apps, and most websites don't work in it, so... basically a dumb phone. But I did write a map web page that works in my very specific situation: https://lab.brainonfire.net/classicmap/ But mostly I just look up directions first and pay attention to signs, and the web page is a fallback that's nice to have.)

Re: Google broke reCAPTCHA for de-googled Android users

#603

Earlier quoted context omitted.

> I'm not going to give up reading the test results from my doctor You could just call them.

That misses the point: alternatives will only be available as long as enough people uses them.

I still make and receive calls all the time to get test results from my doctor, I think tons of people still use that option.

Re: Google broke reCAPTCHA for de-googled Android users

#604
post #600

Earlier quoted context omitted.

Having Privacy in the name doesn't mean it's actually privacy preserving. You can't just ignore attack vectors like collusion between signing entities and websites.

Did you read about how it works? Can you precisely describe an attack that defeats it, or are you just throwing names you've heard without actually knowing how Privacy Pass works? Sounds like the latter to me (yes, I read the RFC).

Your tone isn't appropriate. You don't get to assign reading. If you want to convince people of something then clearly state your case. In this instance that would mean outlining the technical argument.

That said, you've got blinders on. You're all over this comment section condescending to people about a particularly clever scheme without considering the various real world objections being raised. Not the least of which is that the vast majority of the tidalwave of legislation on the topic has zero to do with ZKPs.

Re: Google broke reCAPTCHA for de-googled Android users

#605
post #313

Earlier quoted context omitted.

I have access to a commercial (non-residential), fixed IP. You could also use an outgoing relay as a compromise, since presumably the issue you are facing is other servers rejecting email that you send from a disreputable IP. That being said, you really want a fixed IP as a matter of convenience if you are going to self-host anything.

How often are your emails being marked as spam, for others? A few years ago it read like there’s a whole science behind avoiding getting flagged. Is this easier now with agents aiding the setup?

Not very often at all, but it did happen at least once. Note that even email sent from Google itself can be marked as spam depending on the message.

Re: Google broke reCAPTCHA for de-googled Android users

#606

Earlier quoted context omitted.

I think you and I move in very different social circles... I would have no idea how, nor desire to purchase a Google account on the black market, and I do in fact still trust that my web browser can do TLS correctly.

I meant "corporations do not trust users who register from a web browser and not from a mobile app". Without a mobile app (which allows to collect more hardware identifiers and spam you with notifications) you are not welcome.

Ah got it - I guess I was having a slow day that day.

Re: Google broke reCAPTCHA for de-googled Android users

#607

Earlier quoted context omitted.

I think you and I move in very different social circles... I would have no idea how, nor desire to purchase a Google account on the black market, and I do in fact still trust that my web browser can do TLS correctly.

My reading of codedokode: "easier just to buy a Google account ...." for those who would choose to do that in quantity . That is, the scammers and fraudsters for whom this is a financial decision. Which suggests that Google's latest moves shift the needle only slightly against actual abuse at a huge cost to the rest of us. "Nobody trusts web browsers ..." applies to the publishing side. Content (that is, advertiser)…

You're right, thanks - that makes more sense.

> In conclusion, Google must be destroyed

Yeah they've had their time XD

Re: Google broke reCAPTCHA for de-googled Android users

#608
post #600

Earlier quoted context omitted.

Did you read about how it works? Can you precisely describe an attack that defeats it, or are you just throwing names you've heard without actually knowing how Privacy Pass works? Sounds like the latter to me (yes, I read the RFC).

Your tone isn't appropriate. You don't get to assign reading. If you want to convince people of something then clearly state your case. In this instance that would mean outlining the technical argument. That said, you've got blinders on. You're all over this comment section condescending to people about a particularly clever scheme without considering the various real world objections being raised. Not the least of w…

> Not the least of which is that the vast majority of the tidalwave of legislation on the topic has zero to do with ZKPs.

That's not what I see. I mostly see people complaining about the fact that "if they verify my age, it fundamentally means that I have to give them my ID, and I don't want that". And whenever I mention that technically, there are ways to do age verification in a privacy-preserving manner, I get something like "you are so naive, nobody wants age verification, it's THEM (the all corrupt politicians who all have the exact same opinion) against US THE PEOPLE who need to fight for our freedom!

That is very frustrating to me, because

1. I believe that it is counter-productive to be technically wrong by saying "it is fundamentally not possible". Because if politicians genuinely listen to that, then ask a few cryptographers and get the answer "no actually it exists", then it seems only fair that those politicians will just dismiss the whole opposition by saying "oh right, they are just libertarians who don't want regulations and hide behind incorrect technical claims".

2. I believe that many, many people actually are in favour of age verification to protect their kids. And again, yelling at them saying "you understand nothing, this is not technically possible, and the politicians are all corrupt authoritarians anyway" is not constructive. Moreover, "normal" people don't give a shit about the privacy issues, so if they want age verification, they will just accept any technical solution. I would hope for technically savvy people to try to raise the privacy concerns and explain that if there MUST be age verification, AT LEAST it should be done in a privacy-preserving manner.

But yeah, let's keep yelling that it is fundamentally impossible, such that nobody even hears about the privacy-preserving solutions, until we have to either give our ID to random websites or stop using the Internet. Because what seems clear to me is that we are going towards age verification anyway, and there is zero constructive discussion about how to do that right.

Re: Google broke reCAPTCHA for de-googled Android users

#609

Earlier quoted context omitted.

Tor does it by being so painfully slow an unreliable that the only way you would use it is if there is a cocaine-style reward at the end of it.

> Tor does it by being so painfully slow an unreliable I do 95% of my web browsing via Tor Browser and it is very tolerable, most circuits are fast enough for 1080p video (Youtube, Twitch livestreams, etc) without any buffering. Here is a speedtest I ran just moments ago, I would hardly consider this "painfully slow": https://www.speedtest.net/result/19172283165.png Of course this is a single tor circuit with an exit…

Do you add uBlock Origin to Tor? I know that it is not recommended.

Re: Google broke reCAPTCHA for de-googled Android users

#610
post #608

Earlier quoted context omitted.

Your tone isn't appropriate. You don't get to assign reading. If you want to convince people of something then clearly state your case. In this instance that would mean outlining the technical argument. That said, you've got blinders on. You're all over this comment section condescending to people about a particularly clever scheme without considering the various real world objections being raised. Not the least of w…

> Not the least of which is that the vast majority of the tidalwave of legislation on the topic has zero to do with ZKPs. That's not what I see. I mostly see people complaining about the fact that "if they verify my age, it fundamentally means that I have to give them my ID, and I don't want that". And whenever I mention that technically, there are ways to do age verification in a privacy-preserving manner, I get som…

> Because what seems clear to me is that we are going towards age verification anyway

This is one of the reasons you're getting a lot of arguments here. Every bit of energy spent saying "actually, check out this use of cryptography that lets you do this in a privacy-preserving way" is energy not spend saying "no, not under any circumstances" and fighting against it.

Post reply on HN