Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

Scheduled Pinned Locked Moved Uncategorized
29 Posts 17 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nixcraft@mastodon.socialN nixcraft@mastodon.social

    Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

    Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

    cimeesia@o3o.caC This user is from outside of this forum
    cimeesia@o3o.caC This user is from outside of this forum
    cimeesia@o3o.ca
    wrote last edited by
    #3

    @nixCraft just made this meme after seeing this 😂

    > The iOS comparison is revealing because Apple devices running iOS 16.4 or later complete the same verification without installing any additional apps. Google didn’t demand iPhone users install Google software to pass the test. Only Android users who refuse Play Services get locked out. The asymmetry reveals what this is really about: not security, but ecosystem control.

    Link Preview Image
    1 Reply Last reply
    0
    • agowa338@chaos.socialA agowa338@chaos.social

      @nixCraft So you can't use Amazon Fire tables either?

      That can be fun, lets see what Amazon does against this 😄

      serk@neopaquita.esS This user is from outside of this forum
      serk@neopaquita.esS This user is from outside of this forum
      serk@neopaquita.es
      wrote last edited by
      #4

      @agowa338

      @nixCraft i dont think so. There must be an ad-hoc solution. Same for iphone.

      agowa338@chaos.socialA 1 Reply Last reply
      0
      • nixcraft@mastodon.socialN nixcraft@mastodon.social

        Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

        Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

        maat@mastodon.socialM This user is from outside of this forum
        maat@mastodon.socialM This user is from outside of this forum
        maat@mastodon.social
        wrote last edited by
        #5

        @nixCraft then let's get rid of Android Phones and live to linux ones. If only oss contributors moved to linux mobiles and started to provide mobile apps for linux on mobiles it would change the world... ONG and public EU administrations would move, mobile constructors to avoid loosing critical customers would provide at least some phones with linux and Google would step back in the end.

        mihamarkic@mastodon.socialM asterisk@social.linux.pizzaA 2 Replies Last reply
        0
        • serk@neopaquita.esS serk@neopaquita.es

          @agowa338

          @nixCraft i dont think so. There must be an ad-hoc solution. Same for iphone.

          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.social
          wrote last edited by
          #6

          @serk @nixCraft

          According to the article you just don't have to have the Google Play Services on iPhone. Google only demands them for Android phones.

          Tbh this feels like they're just trying to do a malicious compliance thing with the #DMA. They got slapped so they're trying the next thing...

          serk@neopaquita.esS 1 Reply Last reply
          0
          • maat@mastodon.socialM maat@mastodon.social

            @nixCraft then let's get rid of Android Phones and live to linux ones. If only oss contributors moved to linux mobiles and started to provide mobile apps for linux on mobiles it would change the world... ONG and public EU administrations would move, mobile constructors to avoid loosing critical customers would provide at least some phones with linux and Google would step back in the end.

            mihamarkic@mastodon.socialM This user is from outside of this forum
            mihamarkic@mastodon.socialM This user is from outside of this forum
            mihamarkic@mastodon.social
            wrote last edited by
            #7

            @maat @nixCraft Degoogled Android phones or those who support Android apps are still an option - huge and productive developer ecosystem

            1 Reply Last reply
            0
            • nixcraft@mastodon.socialN nixcraft@mastodon.social

              Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

              Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

              mlabowicz@hachyderm.ioM This user is from outside of this forum
              mlabowicz@hachyderm.ioM This user is from outside of this forum
              mlabowicz@hachyderm.io
              wrote last edited by
              #8

              @nixCraft can you spoof it with an updated browser agent string?

              1 Reply Last reply
              0
              • agowa338@chaos.socialA agowa338@chaos.social

                @serk @nixCraft

                According to the article you just don't have to have the Google Play Services on iPhone. Google only demands them for Android phones.

                Tbh this feels like they're just trying to do a malicious compliance thing with the #DMA. They got slapped so they're trying the next thing...

                serk@neopaquita.esS This user is from outside of this forum
                serk@neopaquita.esS This user is from outside of this forum
                serk@neopaquita.es
                wrote last edited by
                #9

                @agowa338

                @nixCraft just finished reading it XD
                Yes as the article said it. This is control over android, and probably degoogle phones will find a fix but it will force them to do suspicious things.

                agowa338@chaos.socialA 1 Reply Last reply
                0
                • nixcraft@mastodon.socialN nixcraft@mastodon.social

                  Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                  Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                  templailloahi@mastodon.socialT This user is from outside of this forum
                  templailloahi@mastodon.socialT This user is from outside of this forum
                  templailloahi@mastodon.social
                  wrote last edited by
                  #10

                  @nixCraft Of course governments are ignoring Google's shenanigans, Google spends a lot of money on them.

                  1 Reply Last reply
                  0
                  • serk@neopaquita.esS serk@neopaquita.es

                    @agowa338

                    @nixCraft just finished reading it XD
                    Yes as the article said it. This is control over android, and probably degoogle phones will find a fix but it will force them to do suspicious things.

                    agowa338@chaos.socialA This user is from outside of this forum
                    agowa338@chaos.socialA This user is from outside of this forum
                    agowa338@chaos.social
                    wrote last edited by
                    #11

                    @serk @nixCraft

                    One petty thing to do would be to just patch the user agent for these devices to say they're iPhones...

                    1 Reply Last reply
                    0
                    • nixcraft@mastodon.socialN nixcraft@mastodon.social

                      Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                      Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                      maunzcache@ruhr.socialM This user is from outside of this forum
                      maunzcache@ruhr.socialM This user is from outside of this forum
                      maunzcache@ruhr.social
                      wrote last edited by
                      #12

                      @nixCraft If it doesn't work, pressure the website owners and bring down the captcha monopol.

                      Edit: It probably violates accessiblity requirements as well...

                      1 Reply Last reply
                      0
                      • nixcraft@mastodon.socialN nixcraft@mastodon.social

                        Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                        Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                        R This user is from outside of this forum
                        R This user is from outside of this forum
                        rufus01@mastodon.social
                        wrote last edited by
                        #13

                        @nixCraft when will the new captcha be in production ?

                        asterisk@social.linux.pizzaA 1 Reply Last reply
                        0
                        • nixcraft@mastodon.socialN nixcraft@mastodon.social

                          Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                          Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                          musiquenow@todon.euM This user is from outside of this forum
                          musiquenow@todon.euM This user is from outside of this forum
                          musiquenow@todon.eu
                          wrote last edited by
                          #14

                          @nixCraft

                          Google slogan: Be REALLY Evil

                          1 Reply Last reply
                          0
                          • nixcraft@mastodon.socialN nixcraft@mastodon.social

                            Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                            Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                            spacebug@n3.mikronod.seS This user is from outside of this forum
                            spacebug@n3.mikronod.seS This user is from outside of this forum
                            spacebug@n3.mikronod.se
                            wrote last edited by
                            #15

                            @nixCraft so I guess there will be some website that I will not be visiting then.
                            Too bad for them..

                            1 Reply Last reply
                            1
                            0
                            • R relay@relay.infosec.exchange shared this topic
                            • maat@mastodon.socialM maat@mastodon.social

                              @nixCraft then let's get rid of Android Phones and live to linux ones. If only oss contributors moved to linux mobiles and started to provide mobile apps for linux on mobiles it would change the world... ONG and public EU administrations would move, mobile constructors to avoid loosing critical customers would provide at least some phones with linux and Google would step back in the end.

                              asterisk@social.linux.pizzaA This user is from outside of this forum
                              asterisk@social.linux.pizzaA This user is from outside of this forum
                              asterisk@social.linux.pizza
                              wrote last edited by
                              #16

                              @maat @nixCraft

                              Linux is a terrible option for general security, which is especially important for a device as personal as your phone. Nothing is encrypted and Flatpak's sandboxing is worse than Android 4.4 and grants broad permissions by default.

                              maat@mastodon.socialM 1 Reply Last reply
                              0
                              • R rufus01@mastodon.social

                                @nixCraft when will the new captcha be in production ?

                                asterisk@social.linux.pizzaA This user is from outside of this forum
                                asterisk@social.linux.pizzaA This user is from outside of this forum
                                asterisk@social.linux.pizza
                                wrote last edited by
                                #17

                                @rufus01 @nixCraft Considering many haven't updated from reCAPTCHAv2 I don't think we'll see this much.

                                1 Reply Last reply
                                0
                                • nixcraft@mastodon.socialN nixcraft@mastodon.social

                                  Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                                  Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                                  asterisk@social.linux.pizzaA This user is from outside of this forum
                                  asterisk@social.linux.pizzaA This user is from outside of this forum
                                  asterisk@social.linux.pizza
                                  wrote last edited by
                                  #18

                                  @nixCraft The funniest part is that a lot of apps use Google libraries (which means most "degoogled" setups aren't actually degoogled) which can act like a copy of Play Services themselves, so those apps could be a viable option for verification if Google insists on an app, but Google's gotta have that invasive Play Services access, right?

                                  edit: Blog post because the article above doesn't cite its sources:

                                  Link Preview Image
                                  Introducing Google Cloud Fraud Defense, the next evolution of reCAPTCHA | Google Cloud Blog

                                  Today at Next ‘26, we’re launching Google Cloud Fraud Defense, the trust platform for the agentic web and the next evolution of reCAPTCHA.

                                  favicon

                                  Google Cloud Blog (cloud.google.com)

                                  1 Reply Last reply
                                  0
                                  • nixcraft@mastodon.socialN nixcraft@mastodon.social

                                    Google Broke reCAPTCHA for De-Googled Android Users https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users

                                    Google has tied its next-generation reCAPTCHA system to Google Play Services on Android, meaning anyone running a de-Googled phone will automatically fail verification when the system decides to challenge them. Another day another Google take over the world, open web and mobile ecosystems. This battle seems to be lost already because governments are ignoring shenanigans of Google.

                                    O This user is from outside of this forum
                                    O This user is from outside of this forum
                                    oioi@techhub.social
                                    wrote last edited by
                                    #19

                                    @nixCraft So, when you see the QR on your laptop, you'll need to scan it with your phone? I guess, this should reveal who (Google account) is trying to open the site.

                                    1 Reply Last reply
                                    0
                                    • asterisk@social.linux.pizzaA asterisk@social.linux.pizza

                                      @maat @nixCraft

                                      Linux is a terrible option for general security, which is especially important for a device as personal as your phone. Nothing is encrypted and Flatpak's sandboxing is worse than Android 4.4 and grants broad permissions by default.

                                      maat@mastodon.socialM This user is from outside of this forum
                                      maat@mastodon.socialM This user is from outside of this forum
                                      maat@mastodon.social
                                      wrote last edited by
                                      #20

                                      @asterisk @nixCraft Linux is not terrible at all if setup properly. A linux with a decent Apparmor setup is really good for security.
                                      Flatpak is a shame and Android too: It lets Whatsapp and LinkedIn apps slurp all the contacts without even blinking. All Android sandboxing currently just suck.
                                      Only things like island work a little to isolate rogue apps. And nothing protect users from Google on Android.

                                      asterisk@social.linux.pizzaA 1 Reply Last reply
                                      0
                                      • maat@mastodon.socialM maat@mastodon.social

                                        @asterisk @nixCraft Linux is not terrible at all if setup properly. A linux with a decent Apparmor setup is really good for security.
                                        Flatpak is a shame and Android too: It lets Whatsapp and LinkedIn apps slurp all the contacts without even blinking. All Android sandboxing currently just suck.
                                        Only things like island work a little to isolate rogue apps. And nothing protect users from Google on Android.

                                        asterisk@social.linux.pizzaA This user is from outside of this forum
                                        asterisk@social.linux.pizzaA This user is from outside of this forum
                                        asterisk@social.linux.pizza
                                        wrote last edited by
                                        #21

                                        @maat @nixCraft AppArmor and SELinux aren't really comparable to Android's ssndboxing model, which also handles app signing and certificate pinning.

                                        Android's sandbox does not suck (bold of you to say when most Flatpaks can escape the sandbox by editing your .bashrc), Google just requires OEMs to bypass it for Play Services to obtain CTS certification (required to use the Android trademark). Alternate Android-based OSes are very secure (as long as they keep up with security patches, /e and iode do not). GrapheneOS's sandbox for it resolves this issue, letting you use it for apps that need it without security compromises.

                                        A lot of Android's security also comes from verified boot (OS image is read-only and signed, bootloader checks the hash against the one burned in at manufacture or stored in the secure enclave at boot to ensure nothing is compromised) and a hardware secure enclave (which is not a TPM chip, its better)

                                        edit: contact scopes (which GrapheneOS has had for ages) are coming in Android 17 to fix that issue.

                                        maat@mastodon.socialM 1 Reply Last reply
                                        0
                                        • agowa338@chaos.socialA agowa338@chaos.social

                                          @nixCraft So you can't use Amazon Fire tables either?

                                          That can be fun, lets see what Amazon does against this 😄

                                          life_is@no-pony.farmL This user is from outside of this forum
                                          life_is@no-pony.farmL This user is from outside of this forum
                                          life_is@no-pony.farm
                                          wrote last edited by
                                          #22
                                          @agowa338@chaos.social @nixCraft@mastodon.social amazon dropped fiteos already.
                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups