Post B63q1WLc32rsuTzJmi by quixote@mastodon.nz
(DIR) More posts by quixote@mastodon.nz
(DIR) Post #B623tL4D7EZKeIvArg by lynnesbian@fedi.lynnesbian.space
0 likes, 3 repeats
sounds like the web is about to get a lot more annoying to use for #grapheneos users and others using #android devices with """compromised integrity""", people without smartphones, people using smartphones with other operating systems, etc.: https://support.google.com/recaptcha/answer/16609652google's new "mobile reCAPTCHA verification" will require you to scan a QR code from either an iOS device with the reCAPTCHA app or an android device with up-to-date google play services.EDIT: this is part of google's new "fraud defense" system, and is (seemingly) intended to be used for more "important" things like purchases rather than just e.g. comment sections. however, there's nothing stopping site owners from using this thing everywhere
(DIR) Post #B624IFnHrE2lXDsyUC by artemist@mildlyfunctional.gay
0 likes, 0 repeats
@lynnesbian i guess chinese people just won't be able to use websites when traveling
(DIR) Post #B624PZJXgE0e6RSd9c by novet@infosec.exchange
0 likes, 0 repeats
@lynnesbian surely this only applies to google sites right?
(DIR) Post #B624c9RJC1gTcP5qYC by lynnesbian@fedi.lynnesbian.space
0 likes, 0 repeats
@novet i edited my post to clarify, but this is part of a new "fraud defense" system by google: https://cloud.google.com/blog/products/identity-security/introducing-google-cloud-fraud-defense-the-next-evolution-of-recaptcha/it can be used anywhere on any third party site. it seems like they're intending it to be used for "high risk" things like purchase forms, but site owners can, of course, use it anywhere
(DIR) Post #B625DQpJVj2eG569JY by ireneista@irenes.space
0 likes, 0 repeats
@lynnesbian so are we not going to be able to buy anything, since we don't own a smartphone? that's going to be annoying
(DIR) Post #B625DR4CcMx30G42WO by lynnesbian@fedi.lynnesbian.space
0 likes, 1 repeats
@ireneista i foresee a horrible cycle of:google developing The Most Robust ReCAPTCHA Yet to avoid what i'll describe belowopen source hobbyists developing libcaptchaskip and the associated F-droid client that allows you to skip a CAPTCHA by installing a key extracted from the delidded TPM chip of a pixel 6 to avoid the aboveopenclaw et al. integrating libcaptchaskip to allow agents to autonomously buy clothes from temu and sell them on ebay at 400% markup to freeload on the abovegoogle improving their CAPTCHA to avoid the above
(DIR) Post #B625UUx1QhqvyMqFDU by Jes@labyrinth.zone
0 likes, 0 repeats
@lynnesbian all security no privacy
(DIR) Post #B625j38D90ku2H0usy by Dee@fedi.underscore.world
0 likes, 0 repeats
@ireneista @lynnesbian honestly, I can’t remember the last time I had to complete a captcha to do online shopping. I feel like shopping sites are disinclined to make people jump through hoops, cause that makes people less likely to buy stuffI can imagine this being used for, like, logging into Paypal or something similar, though
(DIR) Post #B627LQ48QK5o7hy208 by lynnesbian@fedi.lynnesbian.space
0 likes, 0 repeats
@tizen the barrier isn't scanning the QR, it's that the QR opens the reCAPTCHA app/plugin. on a comptuer, that app doesn't exist, so the QR won't do anything. on an iOS device, you'll need the app, and on android, it's handled by google play services
(DIR) Post #B627wiCvw2sf6VrhhY by networkexception@chaos.social
0 likes, 0 repeats
@lynnesbian ah yes, the classic preventing fraud by pls scan this random qr code 👍
(DIR) Post #B628LNPuN6lRrWh9hg by mo@mastodon.ml
0 likes, 0 repeats
@lynnesbian wow. This is even more user hostile than hCaptcha :neocat_shocked_googly_woozy:
(DIR) Post #B62Bf1NyID2fBhqdpQ by troy_frizzell@mstdn.social
0 likes, 0 repeats
@lynnesbian lol, no.This is right up there with, "Turn off your ad blocker to access."
(DIR) Post #B62Dt8Qt5YML0S4NiS by landelare@mastodon.gamedev.place
0 likes, 0 repeats
@lynnesbian @ireneista Funny that you mention that, recaptcha is the only one I have a skipper browser extension for 🤭
(DIR) Post #B62Ew1ulsXexc7zYKO by abetterjulie@wandering.shop
0 likes, 0 repeats
@lynnesbian they really want me to just stop being online, don't they? That's fine. Think of the money I'll save!
(DIR) Post #B62KBZehDHmSNDhiVs by x0@dragonscave.space
0 likes, 0 repeats
@lynnesbian So if someone is blind and thus can't scan a QR code because they don't have a monitor as it's unneeded, their choices are HCaptcha, which they can't use, or ReCaptcha, which they historically could use but now might be locked out of for high-stakes things like, you know, logging into their fucking bank? HCaptcha locked me out of PayPal for a while!
(DIR) Post #B62Lig5UQ4VrphaMqW by ireneista@irenes.space
1 likes, 0 repeats
@Dee @lynnesbian well, it's been many years since Paypal would let us in (it got hard after we transitioned, and then moving countries on top of that made it so they just lock us out immediately, even when we make new accounts)so at least we know that one won't be a practical barrier, sigh
(DIR) Post #B62M0ShAwxRnVhh1aC by bobmagicii@phpc.social
0 likes, 0 repeats
@lynnesbian this mostly depends on how many devs actually implement it.the new google enterprise captcha library is such a pain in the ass i ended up throwing away the entire project to update it off recaptcha v2 and am still looking for one that doesn't piss me off as much as hcaptcha.just getting the damn thing to handshake with an api key sucks mega now compared to older libs.
(DIR) Post #B62XxiXInSzNDkX4lM by rayotron@mstdn.social
0 likes, 0 repeats
@lynnesbian I wonder if making activitypub based buying, selling, and banking platforms is possible. I mean, can't we replace the internet we're forced to use with one we'd like to use?
(DIR) Post #B62cHHEQQJma96HjyC by ai6yr@m.ai6yr.org
0 likes, 0 repeats
@lynnesbian gaaahhhhhhhh
(DIR) Post #B62cczupU7TIoOTbw8 by Microplastics101@mstdn.social
0 likes, 0 repeats
@lynnesbian Thats me out I wont run play or services on my device. And to require it to view a site is just not going to happen
(DIR) Post #B62jB5hx3TUuLa5qRk by farshidhakimy@chaos.social
0 likes, 1 repeats
@lynnesbian I tried this qr code on GrapheneOS and verification worked without an error.I guess it just needs basic integrity?
(DIR) Post #B62kcvUOk0FiiWafdA by brib@bribstodon.xyz
0 likes, 1 repeats
@lynnesbian @ireneistaI made it into a meme(Meme image and alt text found at https://mastodon.social/@elgringomexicano/116529735970246557)
(DIR) Post #B62kqjPMSIqNImojce by lynnesbian@fedi.lynnesbian.space
0 likes, 0 repeats
@farshidhakimy let's hope it stays that way then.still, this will only work for those with google play services installed afaict.
(DIR) Post #B62lHIYAQ9VRp2bWVc by Tock@corteximplant.com
0 likes, 0 repeats
@lynnesbian This appears to be the web attestation format that was brought to light and shot down before Trump took office. Here it is again, challenging users not to only identify themselves, but "prove your device is worthy of accessing our data. Only authentic Android and iPhones may roam here."Same shit, different banner.
(DIR) Post #B62m02e6OoW3WkiQt6 by Tock@corteximplant.com
0 likes, 0 repeats
@lynnesbian @farshidhakimy The Web Attestation stuff started off with "it's up to sites to determine what security" so the hardline "Android and iOS only" setting may not initially be default.But as people get used to these checks, not hard to guess Google will make new sites use harsher defaults before eventually making the hardnose option the only one in the future in the name of "security."
(DIR) Post #B62mJF8OBvotlI2QJE by ryanc@infosec.exchange
0 likes, 0 repeats
@lynnesbian oh fuck that
(DIR) Post #B62qzu2osW7ycb1w4O by gullevek@famichiki.jp
0 likes, 0 repeats
@lynnesbian @imikotoba Yeah. Of course this is just to make the internet better. Right. Eh. Nudge nudge. Wink wink
(DIR) Post #B63clLHW7o8gYH1lnU by better_bovine@ieji.de
0 likes, 0 repeats
this is fucking disgusting, even if it were only for supposedly important things it's an insane double standard and makes everyone less safe, you shouldn't have to sign up to a google service, even download an app operated by them, to do ANYTHING. i wish people still cared at all about monopolies and consumer protection
(DIR) Post #B63q1WLc32rsuTzJmi by quixote@mastodon.nz
0 likes, 0 repeats
@lynnesbian Yeah, I've started coming across this shit on archive.today. If you click on the eye icon at the bottom, that gets you back to the old, very annoying, grids of cars, bikes, bridges to identify.What is this actually good for? Anybody fraudulent probably has a way of automating that crap in milliseconds. I've always assumed it's the goog getting free training for its self-driving software.
(DIR) Post #B63qeYrWdGJi0FWyVU by nihilistic_capybara@layer8.space
0 likes, 0 repeats
@lynnesbian seriously fuck the corporation controlling the internet. I am just not gonna buy stuff online anymore
(DIR) Post #B64TNtj9hSIM0Jf36O by jigmedatse@social.jigmedatse.com
0 likes, 0 repeats
@lynnesbian Already annoying enough. This'll just be another notch in their belt of enshitification. I wonder how many folk are just going away.
(DIR) Post #B64rVQy2uTae1WkhzU by Tom_Huth@mastodon.online
0 likes, 0 repeats
@lynnesbian Google, otherwise, you have no pains? Honestly an App, when I normally don’t trust you? For all the website owners, go ahead if you don’t want clicks and customers.If this is meant to be to stop all the AI, then AI is killing the web as we know it.I currently block several Google services, so I don't see the captcha madness at all and of course I didn't miss the websites depending on it.
(DIR) Post #B66KdtLQNd3eBA259E by lynnesbian@fedi.lynnesbian.space
0 likes, 0 repeats
@quixote i assume the goal is:Good Eggs use a safetynet-compliant android deviceBad Eggs use an android virtual machine or somethingover time, google is able to identify the Bad Eggs as they always use similar spoofed details (e.g. a stock pixel 9 with GPS location in california and zero apps installed) and deny themmeanwhile, Good Eggs who use their phone "properly" are allowed through seamlessly
(DIR) Post #B66SO7nveP341cMGFE by quixote@mastodon.nz
0 likes, 0 repeats
@lynnesbian Allowed through seamlessly? ?? What? I've been doing those idiotic things since what feels like early childhood and they're always the same, always there. Some people actually get on some virtual list of Proper Eggs?Admittedly, I'm generally on a vpn with scripts blocked, OS is linux, browser is a weird thing out of the Paleolithic.Years ago I had trouble with some online thing my utility company required. I finally had to call them up, fight my way through to third level tech support, only to be told I used linux, so I must be a hacker. 🙄 🤣 🧐
(DIR) Post #B6ET8vfQ9HB1G0NMdk by lynnesbian@fedi.lynnesbian.space
0 likes, 0 repeats
@quixote vpn with scripts blocked, OS is linuxi regret to inform you that you are on the Bad Egg list.
(DIR) Post #B6EdUWqq5pIQCkefeC by quixote@mastodon.nz
0 likes, 0 repeats
@lynnesbian Well, that explains it. I guess since I'm already smelling of sulfur I should just embrace the badness, learn how to hack, and make millions.(That's how it works, right? (😆 ))