Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. So many levels of wrong here.

So many levels of wrong here.

Scheduled Pinned Locked Moved Uncategorized
17 Posts 16 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • dpnash@c.imD dpnash@c.im

    @WPalant Just barely an hour ago, I got a phish simulation training email at work that *contained a QR code* with the usual urgent call to action to “do the thing”, in this case, scanning a booby-trapped QR code.

    Jeezus, Google.

    eestileib@tech.lgbtE This user is from outside of this forum
    eestileib@tech.lgbtE This user is from outside of this forum
    eestileib@tech.lgbt
    wrote last edited by
    #3

    @dpnash @WPalant

    One thing I'm happy about is that they're running into the limits of their capability to have the customers they have deliberately dumbed down and disempowered successfully jump through their hoops.

    My bank doubled down on needing their app on a device with either Apple or Google full surveillance os, and enough of their customers were unable to get it to work that they added the option to go back to text 2fa.

    I told them I'm fine with 2FA, give me a token or let me verify with my member card and a smart reader like _how I vote in European elections_. But you don't get to tell me what OS I run.

    J 1 Reply Last reply
    0
    • wpalant@infosec.exchangeW wpalant@infosec.exchange

      RE: https://mstdn.social/@jschauma/116610268796045193

      So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

      But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

      This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

      benjistokman@mast.benstokman.meB This user is from outside of this forum
      benjistokman@mast.benstokman.meB This user is from outside of this forum
      benjistokman@mast.benstokman.me
      wrote last edited by
      #4

      @WPalant or are blind

      1 Reply Last reply
      0
      • wpalant@infosec.exchangeW wpalant@infosec.exchange

        RE: https://mstdn.social/@jschauma/116610268796045193

        So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

        But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

        This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

        c64whiz@oldbytes.spaceC This user is from outside of this forum
        c64whiz@oldbytes.spaceC This user is from outside of this forum
        c64whiz@oldbytes.space
        wrote last edited by
        #5

        @WPalant

        What's really scary to me is the number of sites that will use this simply because it's free. If web sites would say "no" to this like the users do, one would hope Giggle would have to bail on it.

        1 Reply Last reply
        0
        • eestileib@tech.lgbtE eestileib@tech.lgbt

          @dpnash @WPalant

          One thing I'm happy about is that they're running into the limits of their capability to have the customers they have deliberately dumbed down and disempowered successfully jump through their hoops.

          My bank doubled down on needing their app on a device with either Apple or Google full surveillance os, and enough of their customers were unable to get it to work that they added the option to go back to text 2fa.

          I told them I'm fine with 2FA, give me a token or let me verify with my member card and a smart reader like _how I vote in European elections_. But you don't get to tell me what OS I run.

          J This user is from outside of this forum
          J This user is from outside of this forum
          jaj@mastodon.social
          wrote last edited by
          #6

          @eestileib @dpnash @WPalant Unfortunately that did not work for me in the #Netherlands. I had to buy a dedicated GAFAM phone for the bank or choose not to have a #bank account

          cupz@mas.toC 1 Reply Last reply
          0
          • wpalant@infosec.exchangeW wpalant@infosec.exchange

            RE: https://mstdn.social/@jschauma/116610268796045193

            So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

            But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

            This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

            I This user is from outside of this forum
            I This user is from outside of this forum
            ihayes@mastodon.au
            wrote last edited by
            #7

            @WPalant this is so easy to scam Google should be ashamed of even suggesting it.

            1 Reply Last reply
            0
            • R relay@relay.an.exchange shared this topic
            • wpalant@infosec.exchangeW wpalant@infosec.exchange

              RE: https://mstdn.social/@jschauma/116610268796045193

              So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

              But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

              This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

              odr_k4tana@infosec.exchangeO This user is from outside of this forum
              odr_k4tana@infosec.exchangeO This user is from outside of this forum
              odr_k4tana@infosec.exchange
              wrote last edited by
              #8

              @WPalant yeah. The main issue regarding Google's recent actions is that they are doing everything to become a digitally gated community that everyone needs to do basic things. Once you're in, there's no getting out.

              It's dystopian but it's what they're doing. Google, the everything app.

              1 Reply Last reply
              0
              • wpalant@infosec.exchangeW wpalant@infosec.exchange

                RE: https://mstdn.social/@jschauma/116610268796045193

                So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                huntingdon@mstdn.socialH This user is from outside of this forum
                huntingdon@mstdn.socialH This user is from outside of this forum
                huntingdon@mstdn.social
                wrote last edited by
                #9

                @WPalant

                As I frequently say, fuck Giggle. It's as rapacious as Donald Trump.

                1 Reply Last reply
                0
                • wpalant@infosec.exchangeW wpalant@infosec.exchange

                  RE: https://mstdn.social/@jschauma/116610268796045193

                  So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                  But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                  This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                  S This user is from outside of this forum
                  S This user is from outside of this forum
                  spacelifeform@infosec.exchange
                  wrote last edited by
                  #10

                  @WPalant

                  Closes tab.

                  naich@fosstodon.orgN 1 Reply Last reply
                  1
                  0
                  • wpalant@infosec.exchangeW wpalant@infosec.exchange

                    RE: https://mstdn.social/@jschauma/116610268796045193

                    So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                    But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                    This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                    nosenkow@mastodon.socialN This user is from outside of this forum
                    nosenkow@mastodon.socialN This user is from outside of this forum
                    nosenkow@mastodon.social
                    wrote last edited by
                    #11

                    @WPalant something like “show we 10 fingers on your hands to prove you are human” 🤦‍♂️
                    Hint: I personally have only 9 🤷‍♂️ — ‘cos It’s live 🤷‍♂️

                    1 Reply Last reply
                    0
                    • R relay@relay.mycrowd.ca shared this topic
                    • wpalant@infosec.exchangeW wpalant@infosec.exchange

                      RE: https://mstdn.social/@jschauma/116610268796045193

                      So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                      But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                      This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                      reinald@nrw.socialR This user is from outside of this forum
                      reinald@nrw.socialR This user is from outside of this forum
                      reinald@nrw.social
                      wrote last edited by
                      #12

                      @WPalant do they display that only on PC/Mac Web-Browsers? Or do you get that thing on mobile devices as well?

                      1 Reply Last reply
                      0
                      • wpalant@infosec.exchangeW wpalant@infosec.exchange

                        RE: https://mstdn.social/@jschauma/116610268796045193

                        So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                        But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                        This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                        svenja@mstdn.gamesS This user is from outside of this forum
                        svenja@mstdn.gamesS This user is from outside of this forum
                        svenja@mstdn.games
                        wrote last edited by
                        #13

                        @WPalant its also not accessible for me anymore, because I have a hard time scanning QRCodes because I am blind. Wow, now I hate captchas even more.

                        1 Reply Last reply
                        0
                        • S spacelifeform@infosec.exchange

                          @WPalant

                          Closes tab.

                          naich@fosstodon.orgN This user is from outside of this forum
                          naich@fosstodon.orgN This user is from outside of this forum
                          naich@fosstodon.org
                          wrote last edited by
                          #14

                          @SpaceLifeForm @WPalant
                          This is the correct thing to do.

                          1 Reply Last reply
                          0
                          • J jaj@mastodon.social

                            @eestileib @dpnash @WPalant Unfortunately that did not work for me in the #Netherlands. I had to buy a dedicated GAFAM phone for the bank or choose not to have a #bank account

                            cupz@mas.toC This user is from outside of this forum
                            cupz@mas.toC This user is from outside of this forum
                            cupz@mas.to
                            wrote last edited by
                            #15

                            @jaj @eestileib @dpnash @WPalant ASNBank has a "browser code" system that works well without a smartphone. But I concur, shit is Android-Powered to the max here in NL.

                            1 Reply Last reply
                            0
                            • wpalant@infosec.exchangeW wpalant@infosec.exchange

                              RE: https://mstdn.social/@jschauma/116610268796045193

                              So many levels of wrong here. Google’s newest reCAPTCHA “experiment“ tells people to scan a QR code in order to verify that they are human. Yeah, like scanning a QR code displayed by some random website is a good idea in the first place.

                              But of course your ability to scan the code isn’t what verifies your human nature. That QR code merely tells you that you need the reCAPTCHA app (on iOS) or newest Google Play services (on Android). In other words, you have to verify that you own a mobile device and are providing data to Google. Which they promise not to share with the website, like that’s what I’m worried about.

                              This obviously excludes people who don’t have a smartphone, have a de-Googled smartphone or simply don’t want to feed their data to Google. And it again ties a large chunk of the web to Google services. If reCAPTCHA wasn’t evil before (a questionable statement), it definitely is now.

                              zollak@bonn.socialZ This user is from outside of this forum
                              zollak@bonn.socialZ This user is from outside of this forum
                              zollak@bonn.social
                              wrote last edited by
                              #16

                              @WPalant Does this even stop spammers/bots when they have one of the mobile phone farms with racks full of phones?
                              It shouldn't be too hard to just use one of these phones for a quick scan and might even be less effort than solving a captcha?

                              1 Reply Last reply
                              0
                              • wpalant@infosec.exchangeW This user is from outside of this forum
                                wpalant@infosec.exchangeW This user is from outside of this forum
                                wpalant@infosec.exchange
                                wrote last edited by
                                #17

                                @acs No, you don’t understand correctly. I recommend reading the second paragraph.

                                1 Reply Last reply
                                1
                                0
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups