11 ms·
My understanding is that this new reCAPTCHA is basically just remote attestation. Remote attestation doesn't use blind signatures (as that would be 'farmable')
by coppsilgold 5mo ago
My understanding is that this new reCAPTCHA is basically just remote attestation.
Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the Google server logs EK -> AIK conversions an attestation can be trivially traced to your device's EK. This is also why we don't really see and probably never will see online services which offer fake remote attestations, as it will be pretty obvious that the next step of running such a service is getting Google as a customer and having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.
Unless something special is done with this new reCAPTCHA not only are you locking internet services behind TPM chips but you are also surrendering anonymity to Google. Unless you acquire untraceable burners for every service, the new reCAPTCHA will be technically capable to tying all your accounts across all these services together. Much like age verification. It may appear that the service would need to cooperate to link the reCAPTCHA session to your registration but the registration time alone will likely be sufficient (the anonymity set will be all but destroyed).
- dheera 5mo ago> Google didn’t demand iPhone users install Google software to pass the test. Can de-Googled Android phones present themselves as iPhones?
- thaumasiotes 5mo agoCan they present themselves as... web browsers?
- tardedmeme 5mo agoYes, and then they'll get served a QR code that you have to scan on a phone Google approves of.
- clort 5mo agoIn the UK, the Department of Education guidance is that schools should be mobile-phone free. Students use computers to access the web fairly regularly. Guess that would be problematic then, since many schools policies is that mobile phones should be turned off and stored in your bag during the day.
- coppsilgold 5mo agoApple has their own remote attestation infrastructure and you will not be able to impersonate an Apple device without extracting private key material from the secure enclave of a legitimate Apple device or compromising Apple certificate authority private keys.
- lxgr 5mo agoIs this actually available in Safari?
- e28eta 5mo agoSince iOS 16, apparently https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/ https://blog.cloudflare.com/eliminating-captchas-on-iphones-... https://developer.apple.com/news/?id=huqjyh7k https://developer.apple.com/news/?id=huqjyh7k
- tardedmeme 5mo agoIf you run a website, it seems trivial to forward the attestation to someone else by putting the same code up on your website, and getting their device banned from google instead of your own.
- ChadNauseam 5mo agoThe domain in the attestation would be yours, so that wouldn't work
- chadgpt2 5mo agoHow would the phone camera know the domain name of the website displaying the QR code it's scanning?
- eddythompson80 5mo agoThe camera isn't the part doing that verification. The google service serving that "reCAPTCHA" is what's doing that validation. Unless you're using a custom browser that is reporting a different domain to google than the one requesting the reCAPTCHA, google's service will know which domain is which.
- tardedmeme 5mo agoHow does the verification app on your phone know what's in the URL bar on your desktop?
- ranger_danger 5mo agoThe QR code/URL would be generated/requested by the javascript running on the website you're viewing, which knows what's in your address bar.
- tardedmeme 5mo agoIt would be generated by some other website like Amazon. Because I own, say, Meta, I copy these Amazon-generated codes over to Meta, make people scan them on their phones to sign into Meta and then pass the solution back to Amazon so my bots can sign into Amazon.
- getpokedagain 5mo agoStop visiting sites and using services that use reCAPTCHA. Problem solved.
- deleted 5mo ago[deleted]
- tardedmeme 5mo agoWith the new reCAPTCHA this is going to happen because most human visitors will actually be unable to pass the CAPTCHA. It will be interesting to see whether this makes websites ditch reCAPTCHA or whether they literally just don't care about having customers, an attitude that seems to be getting more and more common every day.
- g-b-r 5mo agoOne problem with these things is that businesses have minimal visibility on the amount of users they lose. On the opposite, if they see reports of many visitors not completing the captcha, they're likely to think "Wow so many bots!!! This defense nowadays is indispensable..!". Sometimes you need to pass a captcha even to contact them (if you want to tell them that you can't pass their captcha).
- jbvlkt 5mo agoI wanted to give money to charity and they have whole form protected by recaptcha. So I would have to allow all my personal information and amount donated sent to google (and agree with google terms for data processing). I have contacted them but they did not understand why this is problem they just wanted to protect themself against bots. IMHO unless those things are not disallowed by antitrust laws we have lost.
- vanviegen 5mo agoWe wouldn't want bots throwing money at us!
- thaumasiotes 5mo ago> My understanding is that this new reCAPTCHA is basically just remote attestation. Yes, somehow "parse this QR code" would not have made my top 500,000 list of 'tasks that a human can do more effectively than a computer'.
- lxgr 5mo agoI'm sure some people still remember how to mentally decode QR codes and verify ECDSA signatures from Covid days. Public transit ticket inspectors in my city also seem to be quite proficient at it :)
- g-b-r 5mo agoI don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough". I think it's most likely to be attested by Google remotely; they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone, officially to make better humanity assessments based on it all. For people using a Google account it probably won't make a huge difference, in terms of data collected. If that's how it would work, spoofing would probably be theoretically possible, but it would be easy for Google to detect attestations used by multiple people. Let's not forget that this is an update to a very approximate system, absolute security is not (yet) required. But there's a good chance that it will be extremely hard to sidestep, despite that.
- lxgr 5mo ago> they might be using an app (with enormous access to the phone as the Play Services have) to be able to link a ton of data together, possibly including the local activity on the phone But anything your phone can possibly do in software can be spoofed, so how would that help?
- palata 5mo ago> I don't see any requirement to support hardware attestation in the recaptcha documentation, the Play Services seem to be "enough". Doesn't Play Integrity use hardware attestation, but specifically checking the Google keys? If you use the Play Services on GrapheneOS, you still don't pass Play Integrity because your system is signed by GrapheneOS and not by Google.
- g-b-r 5mo agoNo, Play Integrity is a set of numerous features, and the developers decide which one to use, and how to react to what the api reports. Hardware attestation is one feature, but it's still not used a lot. The most common feature is the check that your Google account really downloaded the app you're using (and that the app wasn't modified); which requires using a Google account, of course. This is what the "pairip" that's been plaguing the store for a year does (it's being added by a ton of apps because adding it only requires enabling a preference in the Play Console).
- rdedev 5mo agoWhen companies like this exist, what is the point of relying of TPM? Looks like the future is bright for VC backed bots https://doublespeed.ai/ https://doublespeed.ai/
- tcoff91 5mo agoWow that is so dystopian.
- dakolli 5mo agoWhy is every startup using that same Serif font now, Garamond or whatever. Is it an LLM design phenomenon? Its kinda ruining that font style for me. Also $1,500 a month for 10 "influencers" is wild. This doesn't seem that sophisticated unless they're doing something special to increase trust scores of accounts. They say they have "in house warming algorithm" which honestly doesn't inspire confidence for me. Whats funny is its almost a certainty (if they are doing things correctly) that they have literal farms of phones (probably in SEA). The only real way to keep trust high is to have a real mobile connection and unique devices. Proxies are okay, but you really need to use the apps on real hardware.
- etaioinshrdlu 5mo agoI think the font is mimicking old Apple ads, eg: https://i.insider.com/5bf8592eb73c284de50e2f28 https://i.insider.com/5bf8592eb73c284de50e2f28
- dakolli 5mo agoAhh, that makes sense.
- alexspring 5mo agoYep. They got hacked in the past, 1k+ smartphones reported. The cost is the attestation keys of a real phone. Once it gets burned, the phone is useless to them. https://www.penligent.ai/hackinglabs/inside-the-ai-phone-farm-what-the-doublespeed-hack-exposed/ https://www.penligent.ai/hackinglabs/inside-the-ai-phone-far...
- varispeed 5mo agoShouldn't that be illegal under GDPR?
- gib444 5mo agoThere are massive exemptions for the prevention and detection of crime And https://gdpr.eu/recital-49-network-and-information-security-as-overriding-legitimate-interest/ https://gdpr.eu/recital-49-network-and-information-security-... : > Recital 49 - Network and Information Security as Overriding Legitimate Interest > The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems,... It's funny how people after all this time think 99 Articles, 173 Recitals and a huge tech lobby equals a water-tight, pro-citizen, impenetrable privacy law with almost no exemptions.
- xinayder 5mo agoWhat crime are you preventing or detecting by verifying you're human?
- deleted 5mo ago[deleted]
- deIeted 5mo agoworth noting that google/twitter/facebook/reddit/others colluded to combine sessions, identifiers, so that any person getting identified on any one session / ip would be identified on all so while this comment is apt, i would ask them what they think of the previous chicxulub impact of the 2012 era collusion - which to this day has not been reported on (just realized emacs bindings work in comments, nice, no ctrl-x tho)
- normie3000 5mo agoI was going to ask for more info on this collusion but you say it wasn't reported. And googling "chicxulub" just gives a volcano. Is this speculation, or has it been confirmed somewhere?
- TJSomething 5mo ago"Chicxulub impact" seems to be functioning as a bit of hyperbole to imply that this collusion was absolutely devastating, by analogy to the K-T extinction event 66 million years ago. Not that I really can tell what this was devastating to. Maybe United States v. Apple (2012), where Hachette Book Group, Inc., HarperCollins publishers, Macmillan publishers, Penguin Group, Inc., and Simon & Schuster, Inc. conspired with Apple to raise ebook prices?
- Sophira 5mo agoI can't say for sure, but is it possible they're referring to the founding of the Internet Association in 2012?[0] I don't think it's that, because the Wikipedia article makes it seem like it was a force for good, but at the time, it wasn't certain at all that it would be that way.[1] Beyond that, I'm not exactly sure what might be meant. [0] https://en.wikipedia.org/wiki/Internet_Association https://en.wikipedia.org/wiki/Internet_Association [1] https://reddit.com/r/technology/comments/xs4qw/google_facebook_ebay_and_amazon_and_create_the/ https://reddit.com/r/technology/comments/xs4qw/google_facebo...
- mijowi 5mo agoColluded how?
- baybal2 5mo ago[dead]
- palata 5mo ago> Much like age verification Age verification as a technical concept can be done in a privacy-preserving manner! Whether or not we want age verification is another debate, but let's stop making wrong technical claims about that: it doesn't help.
- bpfrh 5mo agoReally, how? At some point someone will need to issue a key, which at some point will need to be verified against known good signatures. These signatures will also need to be kept in case of lawsuirs/enforcement, so if somebody gets access they will know you visited that site
- palata 5mo agoWith cryptography. Look at e.g. Privacy Pass, there is an RFC about it.
- maccard 5mo agoRing cryptography does this - given a public key and a set of private keys you can attest that one of the keys signed it but not which one. This lets both Google and you generate a signature and say “this is attested”, without the person verifying it knowing _who_ signed it.
- nullc 5mo agoYou likely need one other step beyond a plain ring signature, often called a linkable ring signature. If you use only a plain ring signature I could get one authenticated key and setup a site that gives away an unlimited number of access tokens with it, and you can't identify which key is doing so in order to kick it out. A linkable ring signature lets you correlate multiple usage but only if they share a common 'context value'. Intelligent selection of the context value results in abusive use inevitably sharing a context so you can exclude or rate limit it, but honest use tends to not share a context so the privacy is preserved.
- Scaled 5mo ago
- nullc 5mo ago> (as that would be 'farmable') It could be contextual, as in each user gets one anonymous id per domain name per day. Multiple uses by the same user at the same domain in the same day are linked. But much of the purpose of these systems is to violate the public's privacy and exert as much surveillance and control as possible. If not for that schemes that mitigate the privacy loss would be a top priority.
- EmbarrassedHelp 5mo ago> having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate. So basically Google can now ban your device from being able to access a huge portion of the internet, in addition to nuking any online presence connected to them. You could wake up one day and find your device blacklisted from the internet, with no chance of ever reaching customer support. What a lovely future