logoalt Hacker News

Google broke reCAPTCHA for de-googled Android users

304 pointsby anonymousiamtoday at 6:45 PM88 commentsview on HN

Related: Google Cloud fraud defense, the next evolution of reCAPTCHA - https://news.ycombinator.com/item?id=48039362

also: Google Cloud Fraud Defence is just WEI repackaged - https://news.ycombinator.com/item?id=48063199


Comments

coppsilgoldtoday at 7:19 PM

My understanding is that this new reCAPTCHA is basically just remote attestation.

Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the Google server logs EK -> AIK conversions an attestation can be trivially traced to your device's EK. This is also why we don't really see and probably never will see online services which offer fake remote attestations, as it will be pretty obvious that the next step of running such a service is getting Google as a customer and having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.

Unless something special is done with this new reCAPTCHA not only are you locking internet services behind TPM chips but you are also surrendering anonymity to Google. Unless you acquire untraceable burners for every service, the new reCAPTCHA will be technically capable to tying all your accounts across all these services together. Much like age verification. It may appear that the service would need to cooperate to link the reCAPTCHA session to your registration but the registration time alone will likely be sufficient (the anonymity set will be all but destroyed).

show 6 replies
Worftoday at 9:49 PM

I don't use Android right now and haven't used Google'd Android for almost a decade. And I won't. If this is the hill I die on, so be it.

I'm not going to use any sort of hardware attestation, especially one controlled by Google. You shouldn't either, even if you have an unrooted Google-certified Android phone.

show 1 reply
buzzwordstoday at 10:37 PM

Given the way Google is going I'm not sure if my next phone will be Android. I am fully aware that I am probably in the minority here. For me the trust is entirely gone.

show 1 reply
thecatappstoday at 9:19 PM

I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least:

- pretended that it wasn't all about invading peoples' privacy.

- done a good ol' fashioned "but Apple does it"

- pretended to be standards-oriented

- advertised it as something completely transparent to the end-user

Seems like that would've caused a lot less backlash while still achieving the goal of having some form of device attestation -- but I'm guessing that's not the real goal.

show 2 replies
cantalopestoday at 9:54 PM

This is crossing the line where the governments should step in and ban/fine google heavilly for this monopol behavior

show 2 replies
pixel_poppingtoday at 10:19 PM

archive.is just asked me for a QRcode scan, I'm so ashame of that crap (it's behind Cloudflare), forcing website visitors to KYC? Are you guys insane!?

the web is ruined if you push for this, this is millions of websites that will suddenly force KYC? What...the...f

https://ibb.co/X9Q6Y84

By KYC, obviously it's because there is very few non-criminal ways to have a SIM without KYC and get a Google account for Playstore without a number, so every website visits will be attached to a real ID.

I don't use a stock Android, right now I literally can't access many websites, this is genuinely crazy.

cornholiotoday at 8:28 PM

It's a move to block competitor AI agents while securing access for your own, classic ladder kick. The market for autonomous agents providing services and doing online work will be gigantic so, unless you want your own bots locked out from ie properties guarded by Amazon, CloudFlare, Microsoft etc., you will need a bargaining chip.

ezekiel68today at 9:06 PM

I don't know why reclaimthenet hasn't embraced the obvious answer: Simply create a new smart device operating system with a fully disentangled cosmos of programs, libraries, APIs, app SDKs, hardware partners, drivers, trust networks, carrier agreements, app stores, documentation, conferences...

show 3 replies
kyrofatoday at 9:57 PM

I don't even have a smart phone, I assume there is some sort of fallback behavior?

show 1 reply
spankibalttoday at 8:21 PM

Time for some lawfare!

show 2 replies
yohannesktoday at 10:03 PM

Isn't reCAPTCHA a spam? This video I watched recently does a nice history and also was enjoyable to watch https://youtu.be/seX_rDEsP6E?si

OutOfHeretoday at 10:11 PM

If there was any remaining doubt whether Google is evil, this settles that yes it is.

ranger_dangertoday at 7:15 PM

Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops.

My ISP regularly changes everyone's IP, and I apparently share an ISP with people who suck, so I get flagged just trying to do all sorts of normal things. Some examples:

- I've never bought anything from Etsy but I'm somehow banned from even viewing their site at all.

- Discord immediately bans me any time I try to create an account.

- Can't buy flights from Delta, always gives a non-descript error.

- Can't buy concert tickets, it thinks I'm a fraudulent buyer.

- Most CF sites produce a "Sorry, you have been blocked" page, or just loop.

- Trying to buy products on a shopping cart will have my order silently flagged/canceled for "VPN usage" (I don't use one).

- Some sites/programs block me for being on the DroneBL or similar lists I did nothing to get onto, and have verified many times that it's not really coming from me.

I just take my business elsewhere... eventually I'll probably just stop using technology at all.

show 7 replies
cyberaxtoday at 10:21 PM

I think it's possible to run the Play Services in an emulator, faking the device type. Google doesn't seem to use the platform attestation for now.

citizenpaultoday at 8:39 PM

For Decades the huge tech companies basically faced no adversity whatsoever. Now for the first time in their existence the massive returned investments in AI they are experiencing ... we will call it pain.

I would say it will be interesting to see what they do but I think rent-seeking, oppression, human rights violations would be more apt.

They were of course trustworthy proviers while they were untouchable but now I know how things are gonna go.

tamimiotoday at 8:14 PM

And soon desktop OSes will follow, if you don’t have TPM you won’t be able to browse half of the internet.

show 3 replies
hackernews682today at 7:08 PM

The gate to the pig pen is closing…

kittikittitoday at 7:46 PM

Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.

show 5 replies
einpoklumtoday at 9:54 PM

Google seems to be putting yet another brick in the garden wall.

superasntoday at 7:25 PM

[dead]

theturtletoday at 7:19 PM

[dead]

ChrisArchitecttoday at 7:42 PM

Related:

Google Cloud fraud defense, the next evolution of reCAPTCHA

https://news.ycombinator.com/item?id=48039362

Google Cloud Fraud Defence is just WEI repackaged

https://news.ycombinator.com/item?id=48063199

oybngtoday at 9:50 PM

Fascinating how posts critical of google continue to fall off the frontpage

show 1 reply