Google's New reCAPTCHA Wants Your Camera Access and 21 Points of Your Hand
reclaimthenet.org
reclaimthenet.org
With as many Ph.D.s as there are at Google, you’d think they’d be smarter than to come up with this. Which is how you know the PMs are in charge, not the smart people.
No firm lasts forever.
Somehow they seem to have more despite not earning it for such a long time.
Sun, Lucent, Yahoo all had massive valuations at their peak but eventually dwindled and got acquired.
It's always possible for a massively valued company to stumble, fall, and become a husk of what it once was. I don't think Google/Alphabet is immune to this even though their absurd cash cow from ads make it very unlikely at this exact moment.
It's interesting the parallels of Google's recaptcha and Cloudflare turnstile.
Cloudflare is free, no image selector, allows VPNs and Tor for the most part, just 0 click with a good ip reputation and 1 click with a bad one.
Recaptcha is paid, trains waymos, sucks millions of hours of human time, asks for camera access, asks for a phone attestation, blocks VPNs/Tor.
Thank god less sites are using ReCAPTCHA.
Looking forward to some other solutions gaining prominence eventually as well.
Like that Anime girl one.
I'm pretty sure, Cloudflare capchas could be endless
Or it goes on forever without passing, which can also happen, and then you simply can't proceed. It also really does not work over TOR in my experience.
I've had it happen a bunch of times, but Recaptch usually falls back to the image challenge if I can't pass V3. It might force me to solve several of them, but it eventually lets me pass.
I even get "Sorry." logging onto HN from time to time (which I think is cloudflare). It usually works again the next day.
If a web requires me to do this to access it, I simply refuse.
The last time I needed some web was my electricity company - sent them a ticket with a complaint. They replied with some bs like "your browser is simply not supported" so I kept sending them the same ticket over and over again until I got a real response and it seems they decided to change the system.
To use my favorite quote: That's all it takes really, pressure, and time... :)
Someone always has to be the first to say "no thanks" to their bs.
A friend of mine recently tried to get a payment from an insurance policy. But the New York Life web site wouldn't work right.
She ended up talking to someone on the phone eventually and they told her it's her fault, because Safari isn't supported. Only Chrome and Edge.
Her choice was to install Chrome, or walk away from $35,000.
You may "just refuse," but she installed the browser and got her money.
Often no % required.
I would still refuse and force them to send the money through snail mail.
Insurance companies are notorious for making it very hard for people to collect money from policies. They are well known for making things deliberately hard so people will give up.
I'd love to see you "force" a massive insurance company to do anything without a lawyer. Real life is not the same as talking big on the internet.
The last time insurance company tried to BS their way out of the insurance payout, I actually did get the lawyer involved and I successfully got them to admit fault and pay up.
Standing up for myself and doing something IRL feels quite good. You do you.
(Apparently, this started appearing from last month - https://cybernews.com/privacy/google-qr-code-recaptcha-requi... ).
Whatdo?
----
This post is hypothetical sarcasm... only two of the above are truthful.
They asked for feedback after I canceled the login, I gave very candid feedback in a form.
Then they asked if I would give an interview.
You know why I wanted to log in? To claim a $7 refund.
They ended up mailing it.
I also make sure they never owe me. Otherwise I get delayed money, ID thieves have another reason to target me, thieves might actually get it, and the IRS might not give it. And the last thing happened to me once with a large refund, for a year, because of a pure logistics error on their end that took me a ton of effort to get them to fix, and it was kinda related to ID. Identity situation is much cleaner if I just pay the IRS.
(this is from the Netherlands where you can use digID [0] to sign into government services and ID-bound 3rd parties like insurance, mortgages, pensions etc)
The internet is dead.
At least I know what kind of hand gesture they will get first :)
I closed and walked away from a long standing account with HSBC when they introduced a requirement in their app for me to have Google Keyboard installed and active as my primary keyboard rather than my own one that I knew wouldn't send my keypresses to Google.
Sometimes all we need is the final push from them declining your business unless you jump through their hoops to agree that it's not worth your time.
Would it deny her hand's reCAPTCHA because it doesn't match my biometrics? Or would it allow her and just make a record in the google database that she was using my phone at 8:42PM ?
For instance, terminalcam, gives just enough data to reveal liveness without necessarily giving enough information about identity.
And seriously - what about people without hands? What about scammers pretending to be Google gaining access to my camera? What about blind people? What about people using the site in places where camera use is not allowed?
Not sure what problem everybody here is having with this. The alternative would be device certificate stuff (ala did Apple sign for this being a proper Apple device?). Having to shake your hand sounds a lot more privacy friendly. Are you guys seriously worried that Google is gonna steal your secret handshakes?
For starters, it's extremely invasive (camera on to pay a bill - wtf?), has unclear privacy implications and questionable accessibility (to put it mildly).
Like seriously, if I have to turn on a camera to get through a recaptcha then the website doing it can fuck right the hell off with extreme prejudice. My web browser is not allowed to access my cameras for any reason, no exceptions.
So stripping away user privacy even more is justified for implementing an already obsolete verification method?
Would also accept having to pay a small amount of cryptocurrency to use a site/service, but that's only suitable for DDoS or mass bot protection, not proof of being human.
Do I really think Google will retain that information for "debugging purposes", and 2 or 10 or 20 years from decide to make a service that identifies me from my hand biometrics because it will make them more money than the class action will cost them? Yes.
Can't be bothered... so instead using the accessibility option of listening to a phrase instead.
> Google does not retain any images or videos of a user's hand gestures
This is the sole statement of data deletion provided, and nowhere does Google state any other retention policy for derivations whatsoever, whether anonymized or associated, from that hand data; referring instead to the generic terms of service privacy policy:
> Other data is deleted or anonymized automatically
The privacy policy does not have a specific callout for biometric derivations, and so they may choose to anonymize rather than delete your biometric data.
> some data we retain for longer periods of time when necessary for legitimate business or legal purposes, such as security, fraud and abuse prevention
Recaptcha exists for the exlclusice purpose of security, fraud and abuse prevention, and so by this clause they may retain your identified hand scan biometrics for as long as they see fit.
> We will share personal information outside of Google if we have a good-faith belief that disclosure of the information is reasonabl[e]
They will give your identified hand biometrics upon request to anyone who can make a convincing case to them.
> We may share non-personally identifiable information publicly and with our partners
And they grant themselves the right to start selling their dataset of humanity’s hand biometrics for personal profit with none shared back to those whose biometrics are now a commodity to be bought and sold.
(Note that Google is not alone in this; see also gestures at much of tech. But that’s no excuse for the grift going unreported by a journalistic entity that’s been around long enough to know better how these reassurance-by-omission scams work. I was already upset with Google but I still expect better of those trying to stop them.)
Seems like they covered your points just fine. They just did it succinctly and trusted the reader to understand the broader implications.
https://reclaimthenet.org/the-house-just-voted-for-kosa
> If you’ve been following our updates, you’ll know the accountability positioning hides the actual design. The bill defines “know” or “knows” to mean “to know or should have known,” and that phrase runs through sections covering platforms, AI chatbots, and gaming services.
In their recent (two days ago) reporting on KOSA, they dedicate an entire paragraph (see above) specifically to explaining how a word choice is being used to hide the main thrust of the bill, and continue on for some paragraphs detailing how a single disguised and misleading word is the beachhead for an affront to privacy. So their failing to call out Google on this word choice reads as 'lack of familiarity with the terrain', as when on more well-understood ground — since US gov't reporting rather predates the tech industry, after all — they do call out such things.