12 ms·
The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 https://support.google.com/recaptcha/answer/166096
by bramhaag 5mo ago
The requirements for the mobile devices are listed here: https://support.google.com/recaptcha/answer/16609652 https://support.google.com/recaptcha/answer/16609652
So it seems that you will need a modern Android device with Google Play Services installed or a modern iPhone/iPad to be allowed to browse the web in the future.
No mention of device integrity verification yet, but the writing is on the wall.
- Hizonner 5mo ago... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site. I know, people will slavishly knuckle under, but let me dream for a few minutes.
- tardedmeme 5mo ago99.999% of people don't give a shit and don't even know what this means. They'll follow the instructions. These are the same 99.999% of people who press win+R ctrl+V enter when the captcha prompts them to. Because do this to see the dancing bunnies.
- mrguyorama 5mo agoThey will do exactly as it says while also ceaselessly complaining, completely unable to connect their choice to use a website with the pain of using that website. There's some sort of serious issue with learned helplessness or something
- ronsor 5mo agoYeah, this is going to turn into another malware vector, isn't it?
- tardedmeme 5mo agoDiscord has a feature where you can log into your account on your PC by scanning a code on your phone. So does Binance.
- mystraline 5mo agoSo does Signal.
- warkdarrior 5mo agoBut Signal is secure(TM)!
- EmbarrassedHelp 5mo agoBut none of those options are requirements to access the service.
- tardedmeme 5mo agoThey're requirements to access my website though! To prove you're not a bot, scan this QR code - with Discord.
- xp84 5mo agoThose are good things though? They’re about logging in, on purpose. Not about attesting to Google that you have a proper smartphone as a proxy for your humanity, like this thing.
- tardedmeme 5mo agoTo prove you're not a bot, scan this QR code with Discord.
- KellyCriterion 5mo ago> press win+R ctrl+V LOL is this real? I guess yes, because yesterday ReCaptcha asked me to screenshot a QR-code with the mobilephone :-D
- EvanAnderson 5mo agoIt is. There are fake Cloudflare CAPTCHAs on pwned Wordpress sites that instruct users to run Powershell scripts.
- snailmailman 5mo agoIt’s a common thing for malware. But people are going to be more likely to fall for it when mainstream sites ask you to complete weird tasks with your phone to verify your identity.
- duskdozer 5mo agoPeople are constantly made to jump through strange hoops to do things on the internet. Unless you're really keyed in to what's going on, it's easy to fall for stuff like that.
- nonamesleft 5mo agoI have blocked it for years with ublock origin, if a site doesn't work, ctrl-w. Nowadays i cannot even use google search because of this, any search will trigger a captcha, hilarious (atleast on chromium-based browsers, firefox lets me get a page or two).
- Leonard_of_Q 5mo agoDitch Google Search as well then, use something like SearXNG or another meta-search engine. You'll get more representative results, no tracking and no captchas. Sometimes some of the engines may return captchas but they're kept from the search results, i.e. those engines don't get used for the query. You can run your own instance of SearXNG or one of the alternatives or use one of the available public instances, your choice. The fewer direct interactions with the likes of Google/Apple/Microsoft/etc. the better.
- conradfr 5mo agoThe thing is even a contact form without something like reCaptcha is doomed on today's web: spam all day.
- 986aignan 5mo agoIf it's just a contact form on some random site that isn't particularly valuable to spammers, a bespoke solution like hidden input fields, obfuscation, or some kind of token calculated client-side by JS will probably work just as well.
- account42 5mo agoThat used to be the case, unfortuantely today even bespoke solutions can be completed by automation - any anything that just requires running JS in a headless browser was ineffective for a long time already.
- hellojesus 5mo agoThis is going to make my grapheneos journey a bit more exciting. How wild to force users through an official google identification for web browsing. Does the iPhone recaptcha app force you to login with a Google account? Seems we didn't need ID verification for the web to lose all anonymity.
- lucb1e 5mo agoI'd rather have to do ID verification at a government site that gives out blindable RSA signatures to browse the web with using open source software, than this overseas tech company needing to lock down the whole device and tech stack and not have to 'show ID' at all. One of these two holds elections... Music/movie corporations and game developers must look forward to an age where people can't access the cache files or hook up a debugger to their apps anymore
- LorenPechtel 5mo agoOne of them pretends to hold elections.
- xp84 5mo agoDoes it only count as an election if one’s favorite side wins?
- achierius 5mo agoWhat if neither side represents your interests? What "election" is there in that case?
- lucb1e 5mo agoThere's more than two sides here. None of the 14 parties with >1 seat in parliament fully represents my best understanding of how to improve the country and world on any time scale (long or short), but quite a few of them come reasonably close and I would vote for them without much hesitation (Heck, I wish there were fewer parties, like if five single-topic good parties (bij1 against racism, pirate party for internet freedoms, volt for international collaboration, party animals for environmental welfare, etc., plus greenworkersparty as the current overarching big boy) would band together, it'd be a much easier choice!) That not every country is so lucky (not all of them have free elections, or elections at all) is a shame indeed, but at least for countries like mine I'd be much happier to have a government arrange a system than a tech corporation and foreign laws. Presuming that the 2-party system you speak of is the USA's, at least both corps are governed by your own laws, that's something!
- everdrive 5mo agoI've been saying for years that it does not make sense to browse the web on a smartphone. Eventually things will get bad enough that people will agree with me.
- fsflover 5mo agoSmartphone is just a small computer. I don't see hiw what you say makes sense.
- everdrive 5mo agoIt's a small computer that I don't really control with a horrible UI, horrible privacy, and nothing but perverse incentives. ("download the app!")
- esseph 5mo agoSounds like Windows
- xp84 5mo agoAnd Mac
- Forgeties79 5mo agoThere’s no going back unfortunately. There’s no world where smartphones go away barring a new tech as significant and useful as a smartphone.
- fsflover 5mo agoWhy are you so sure? Have a look at Librem 5 and Pinephone.
- Forgeties79 5mo agoI’m familiar with projects like them. I just don’t think any of them are going to break through in a meaningful way anytime soon, if ever. They have very niche markets. I hope they are always an option though.
- NotPractical 5mo ago> No mention of device integrity verification yet If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_DEVICE_INTEGRITY is required, that would probably not be explicitly listed here. E.g. the consumer documentation for Google Pay just says you need a "certified" Android device and a screen lock set up: https://support.google.com/wallet/answer/12200245 https://support.google.com/wallet/answer/12200245 (Yes, if you go deep into the FAQ at the end it eventually states that if you rooted your phone, you can't use tap to pay, but that requirement is implied by the certification requirement [1].) In Google's eyes, and in the eyes of the law due to trademarks filed by Google, Android == Google Android. This feature would make little sense if it's not using device attestation because otherwise it would be easy to spoof. I expect that it will initially not use it, and they will start A/B testing device attestation in the coming years. [1] Expand "What to do if you see device is not certified" -> "Reset device to fix issue" https://support.google.com/android/answer/7165974 https://support.google.com/android/answer/7165974
- charcircuit 5mo ago>that implies that a "certified Android" device capable of Play Integrity attestation is required No, it doesn't. It implies that the app for handling the deeplink lives within GMS as opposed to needing to manually install a separate app like you do on iOS. GMS does not have a hard dependency on device integrity APIs being supported.
- blueg3 5mo agoThey said "capable of Play Integrity attestation". It's a weasel statement. If you have GMS, you're capable of performing PIA attestation, you just might fail. So it's strictly true, but doesn't tell us anything about whether it requires PIA.
- NotPractical 5mo ago
- nerdsniper 5mo agoI believe you'll also need bluetooth enabled on both devices. At least you do for those "scan this QR code displayed on your computer to authenticate using the passkey on your phone" feature, which this seems analogous to. Bluetooth is used to ensure that the two devices are actually physically co-located.
- g-b-r 5mo agoIn passkeys the bluetooth is used for the actual authentication protocol...
- nerdsniper 5mo agoSometimes, sort of. Most passkey usage doesn’t involve bluetooth. When it does, there’s no real data being sent over bluetooth, just a meaningless hash that can be confirmed using a secret inside the QR code. So really, it’s like I said, Bluetooth is used to make sure that the device consuming the QR code is actually near the device that’s displaying the QR code.
- hellojesus 5mo agoMy desktop doesn't have Bluetooth. Does this mean I'd be doomed even if I had a compatible mobile device?
- 2ndorderthought 5mo agoWe might need to redo this whole Internet thing because this is insanity.
- CalRobert 5mo agoMaybe it’s time to get in to Ham radio or some other hobby
- hellojesus 5mo agoI'm a licensed ham! Though I've never actually done anything ham-related. I just wanted a license plate with a call sign. But then I learned that anyone can look up my name and home address from my call sign and decided not to publicly advertise when I'm not home.
- deleted 5mo ago[deleted]
- varispeed 5mo ago> but the writing is on the wall. Only if politicians are still corrupt and law enforcement doesn't work. Which means the writing is on the wall.
- Velocifyer 5mo agoI will be unable to solve the phone verification because I use LineageOS for microG, but any fraudster can just buy a bunch of $30 android phones. Many people have trouble using a smartphone, so they use dumbphones, but they will be locked out. Many people just don't have any mobile phone because they don't think that it is useful.
- blueg3 5mo agoGoogle is mostly interested in abuse that happens beyond the scale of how many $30 phones you can buy.
- 2ndorderthought 5mo agoGoogle is interested in, like other tech companies, identifying users by tying them to their phones. Other ai defense companies are trying to get photos and IDs. This is just another take on the same subversive activity.
- Barbing 5mo agoI'm expecting a pretty hard identity verification requirement to connect to the internet, which should solve for the burner phone thing.
- duskdozer 5mo agoThey're mostly interested in having a complete record of all users' internet activity tied uniquely to their identity.
- snailmailman 5mo agoI’m already sick and tired of seeing cloudflares “making sure you aren’t a bot” checkbox everywhere. Sometimes it locks me out entirely and decides I don’t get to view pages. I see recaptcha less frequently but it’s much more annoying, with all the clicking of crosswalks, or busses, or whatever. I am not looking forward to a web where google can not only lock me out of my email, but also large sections of the previously public internet. Occasionally google decides I don’t get to do searches, and that’s not too much of an inconvenience, there are other search engines.
- Gander5739 5mo agoBut what's the alternative? Sites need a way to prevent bots overwhelming them, and there's no perfect way to distinguish real users from bots.
- andrepd 5mo agoYou're right, we need big tech to protect us from the problems big tech created. In the olden 20th century, we had a term for that...
- 2ndorderthought 5mo agoYou know that protection racket where the mobster came to my corner store and says if I don't pay him he will come later and rough me up? This is a worse deal than that.
- mannanj 5mo agothis is the modern version of that.
- PeterStuer 5mo agoBetter turn on that 'free' Cloudflare 'bot' protection. Would be a shame if our, ahem, I mean, those botnets ddos'ed your site.
- 5mo ago
- throwaway613746 5mo ago[dead]
- crazygringo 5mo agoDo you have an alternate solution? When we hear so many stories from HN'ers of their websites being hammered by out-of-control crawling and fetching and new levels of AI slop spam? This is something site owners choose to implement or not. They're the ones paying the extra hosting fees to handle potentially unwanted traffic, and dealing with spam that traditional CAPTCHA's are no longer effective against. Google's not forcing this on anyone else.
- PeterStuer 5mo agoInvestigate the anti-bot sellers.
- crazygringo 5mo agoHuh? Investigate for what?
- duskdozer 5mo agoNo surprises here, though of course disappointment when it comes to fruition.
- ikr678 5mo agoAnd you must be signed in. I frequently get flagged as suspicious activity and have to pass a captcha when trying to use the Google verbatim search function on a signed out Firefox browser on android.
- Angostura 5mo agoI get it all the time on my Mac with Safari using iCloud private relay
- deleted 5mo ago[deleted]
- jeroenhd 5mo ago> And you must be signed in. I don't see any mention of that? Google Play services work fine without an account (although if you're the kind of person who doesn't sign in to a Google account on their Android phone, you're probably running a custom ROM or something)
- adrian_b 5mo agoUntil now, I have never run "a custom ROM or something", but just the Android that came from the phone vendors and its updates. Nevertheless, I do not have a Google account and I do not intend to have such an account. Of course, this means that I cannot install any app from the official Google store, even if it is a free app. The requirement to login into your Google account should have existed only for payments, not for downloading a free app, but nonetheless Google does not work this way. I already had problems with a bank that has terminated its Web-based online service, replacing it with an app that they refuse to provide for downloading, so that I could install it without having to open a Google account. Therefore I have also terminated my accounts with that bank. I hope that this behavior will not spread to all remaining banks that still have Web-based online access.
- Gander5739 5mo agoYou could try aurora store with anonymous accounts, though that has the problem that other people may be able to see the apps you install.
- pjc50 5mo ago"As part of our mission to enable a safe agentic web" drew an immediate swear from me. What's happened here is yet another massive negative externality from AI. Because AI is such a fraud enabler, Google are now using that as an opportunity to end the open internet and competition in operating systems. I'd much rather go the other way and make the AI wear identification. Crack down on both corporate and unlicensed AIs. Edit: and of course it's also advertising killing the web, because the fraud in question is ad fraud. Need to force it into human eyeballs, not bots.
- trollbridge 5mo agoYep. I learned yesterday you can’t sign in to Cursor on Brave Browser. Had to switch to Safari. This is only going to become more and more common.