• schuelermine@leminal.space
    link
    fedilink
    English
    arrow-up
    19
    ·
    7 days ago

    You can install Google Play Services as a sandboxed app on GrapheneOS. That’s not the issue. I believe the issue is that Google will use hardware attestation to check if the OS you’re running it on is Google-approved.

    • FG_3479@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      7 days ago

      The Recaptcha QR code verification does work on GrapheneOS for now and there is a standard select the swuares fallback. Recaptcha is also entirely optional for a website and they can easily pick any competitor like hCaptcha if they want.

  • korazail@lemmy.myserv.one
    link
    fedilink
    English
    arrow-up
    7
    ·
    7 days ago

    For a decade or two now, it’s been pretty much assumed that everyone has an internet-connected, camera-equipped, browser-capable device in their pocket. Restaurants, banks, hospitals, employers and even government offices use QR codes and websites to get you to their menus, forms or services.

    If ID is being tied to my mobile spy device, then I need my mobile spy device to be a right and not a luxury. $40-50 for a few years of validity, internet access provided at no cost, even if slow. I can have my luxury phone be where I’m ‘anonymous’, but I want the government to subsidize the mobile spy device if it’s a mandatory expense. Even cheap phones cost a lot of money.

    To be clear, I don’t want ID tied to my phone, but it’s gotten harder to exist without one, so it should be something we have access to with minimal friction.

    Add food, water and shelter to that list, but you can’t ask for them without a web browser.

  • epicshepich@programming.dev
    link
    fedilink
    arrow-up
    9
    arrow-down
    1
    ·
    7 days ago

    Most of the time, my phone’s browser is disabled. It keeps me from using my phone too much. I understand not everyone is in a position where they can do that though.

  • AmbitiousProcess (they/them)@piefed.social
    link
    fedilink
    English
    arrow-up
    250
    ·
    9 days ago

    This is really bad even just from the perspective of user behavior. Training people to scan QR codes from anything that looks like a captcha box is HORRIBLE for security.

    “Thanks for scanning the code, just one more step! Please input your phone number, and type in the code you receive.”

    Boom, account stolen.

    • LeapSecond@lemmy.zip
      link
      fedilink
      arrow-up
      18
      ·
      8 days ago

      And the phone number thing is already happening too. Google, discord and probably other stuff already ask for a phone number to prove you are a human when they flag your account.

      • InFerNo@lemmy.ml
        link
        fedilink
        arrow-up
        5
        ·
        8 days ago

        It’s a server setting. one of my oldest servers has enabled this and I haven’t chatted with anyone there anymore because I need to verify my phone first.

    • Tore@piefed.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      8 days ago

      That would make the two of us. My Fairphone 3+ is still kicking well with /e/OS.

    • s38b35M5@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      8 days ago

      And nothing of value was lost. I’m over social media, over commercial apps, and maybe I’m over having a mobile phone, too.

  • Phoenixz@lemmy.ca
    link
    fedilink
    arrow-up
    165
    ·
    8 days ago

    If google requires me to permit other companies to leech all my personal data to be able to use anything on the Internet at all, I say we label Google, Microsoft, Apple as criminal organizations

    I’m sorry, bit there have to be limits.

    I. DO. NOT. WANT. TO. USE. ANYTHING. GOOGLE.

    OR APPLE. OR MICROSOFT.

    FUCK ALL THESE OLIGARCH COMPANIES INTO THE GROUND

    I do not want my private data leeches and sold every day, I don’t even get paid for it

    • Batmorous@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      8 days ago

      That and fine them to oblivion. Piece their companies into parts. Make it all open source for the OS’es. Give ownership of companies to all the people. Etc. Lots and lots that can be done

    • jafra@slrpnk.net
      link
      fedilink
      arrow-up
      6
      ·
      8 days ago

      I almost came reading this rant. Thanks for bringing this so much more eloquently to the point.

    • bagsy@lemmy.world
      link
      fedilink
      arrow-up
      24
      ·
      8 days ago

      Every company that uses these captcha service should also be fined so hard. This isnt just google here.

      • jafra@slrpnk.net
        link
        fedilink
        arrow-up
        8
        ·
        8 days ago

        And every company that is relying on gsm or the apple pendant to verify anything.

    • Batmorous@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      8 days ago

      And forced to open-source their OS’es. And have to make their communities owned by the people instead of corpos. We are all beyond pissed and done with their shit. Everyone get more people on board into the movement daily to be focused on getting things done together!! Keep each other in the fight with online and in-person communities

  • Freakazoid@lemmy.ml
    link
    fedilink
    arrow-up
    78
    ·
    8 days ago

    Let’s hope the EU prevents this from happening. We should be able to access every site we wish without Google’s permission.

    • Batmorous@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      8 days ago

      We should all be encouraging Europeans to:

      1. Force Android and iOS to be given to the people to own and open-source the OS fully in EU with GPL license
      2. Fine them to oblivion if they do not cooperate
      3. If they try to double down then piece up their companies into parts

      We all tired of their fucking shit. Everyone keep getting people active and informed on all this!! Together anything is possible!!

    • eleitl@lemmy.zip
      link
      fedilink
      arrow-up
      9
      arrow-down
      20
      ·
      edit-2
      8 days ago

      The EU is busily building the Fourth Reich, so don’t expect help from there.

        • Narri N. (they/them)@lemmy.ml
          link
          fedilink
          arrow-up
          8
          ·
          8 days ago

          The ongoing battle against online privacy is a symptom of capitalism, the EU is a capitalist state. The only thing the EU would ever do against US-based capitalism is to gobble up those capital gains for themselves. It doesn’t matter if it happes or not, the privacy-issues for end-users would never be alleviated by the EU.

          • Alaknár@sopuli.xyz
            link
            fedilink
            arrow-up
            1
            arrow-down
            2
            ·
            7 days ago

            From what you’re saying, they would’ve already introduced all those capitalist methods of control the first time around.

            Which they didn’t.

            What gives?

            Also: the EU is literally incapable of “gobbling up capital gains for themselves” because “themselves” doesn’t exist in this context - the EU is not a “State”. The member-states might (and some do).

      • lsjw96kxs@sh.itjust.works
        link
        fedilink
        Français
        arrow-up
        8
        ·
        8 days ago

        Yeah, sure, at a really slower pace than USA. Maybe in a century. They still care more for their citizens Trump ever did.

  • AmbitiousProcess (they/them)@piefed.social
    link
    fedilink
    English
    arrow-up
    48
    arrow-down
    1
    ·
    9 days ago

    This does seem to work with sandboxed Google Play Services on GrapheneOS btw.

    I scanned the demo QR code on Google’s talk page about it with sandboxed Play Services enabled and it gave me a custom popup asking if I’d like to verify.

      • krashmo@lemmy.world
        link
        fedilink
        arrow-up
        31
        ·
        9 days ago

        Unless you’re doing that from a separate device in a separate location then all you’re doing is giving them the data they need to link those two accounts

        • FauxLiving@lemmy.world
          link
          fedilink
          arrow-up
          20
          ·
          8 days ago

          You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.

          Sandboxed Google Play Services doesn’t have privileged access to location information, so it can’t pull your GPS location or Wifi Positioning information. It would only see a blank profile and doing this would allow for your primary profile to continue to not run Play Services.

          Any malicious code which could be injected into the process would find itself in a sandbox, on a blank profile and isolated from the rest of the system.

          Google would only see that you are authenticating from a profile without anything installed, from an unknown location and coming from whatever VPN endpoint that you’d like. They could possibly infer that the blank profile and your ‘real’ profile are different via browser fingerprinting. You can randomize a lot of fingerprinting datapoints with browser extensions, but avoiding browser fingerprinting is a whole other topic.

          The ‘real’ privacy solution is to avoid anything that uses this version of recaptcha. However, if you have to use these services then you can still reduce the amount of information leaked via Play Services by using a blank profile to scan the QR codes.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            19
            ·
            8 days ago

            You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.

            its not even about complete anonymity. google has zero business in when I’m logging into my utilities company account, or other semi-governmental portals!

            • eldavi@lemmy.ml
              link
              fedilink
              English
              arrow-up
              7
              arrow-down
              6
              ·
              8 days ago

              it literally is their business; they make millions of dollars off of it.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                8 days ago

                then that’s a problem we must solve. Because an adtech company should definitely not have any business in that.

                • eldavi@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  8 days ago

                  it has been solved for approximately 2 billion people on this planet, but those answers are not friendly to profit-seeking institutions like google and the only remaining institutions that can stop it are captured by the likes of google

  • Sarcasmo220@lemmy.ml
    link
    fedilink
    arrow-up
    47
    ·
    8 days ago

    Eventually privacy minded people like us will have to start creating and visiting sites on the dark web.

    • Patrikvo@lemmy.zip
      link
      fedilink
      arrow-up
      8
      ·
      8 days ago

      Sheesh, using alternative sites instead of Facebook and Reddit isn’t using the dark web.

      • topperharlie@lemmy.world
        link
        fedilink
        arrow-up
        16
        ·
        8 days ago

        if they add this requirement for the “I’m not a robot” technology this affects way more than stupid Facebook, reddit and the likes, most things behind anti DDoS use this shit.

        I find this very dystopian, and there are not many “oh I’ll just visit the sites than don’t have it” alternatives. You might as well just open IRC and be done with it, I tend to visit a bit more of the internet (even if I haven’t visited Facebook, Instagram and the likes in years)

        • FineCoatMummy@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          6
          ·
          8 days ago

          Ayup absolutely. Those co’s have such weight. They can drive this into essential services. Banks. Gov services. All online stores. Heck even sites that don’t need logins.

          It’s short sighted to say “I’ll just use other sites then”. The end of that road is, we get excluded from modern life.

          You’re so right, it’s dystopian.

    • Batmorous@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      8 days ago

      No fuck that we must continue to grow the movement and get more people on board. We don’t give in to those rats and their garbage they try to put on us. Together we all can do together. Fuck them. Many of us already are doing and the more the better

    • eleitl@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      8 days ago

      No need for that, just spin up a nginx with letsencrypt certs. Most people don’t need Cloudflare.

  • meowmeow@quokk.au
    link
    fedilink
    English
    arrow-up
    43
    arrow-down
    1
    ·
    9 days ago

    Can we trust that isn’t a campaign to promote Google? What are these websites? Why aren’t they blocking an iPhone? Can any of that be replicated or is this just a Google campaign to create fear and doubt