frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Google Broke reCAPTCHA for De-Googled Android Users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
41•anonymousiam•1h ago

Comments

hackernews682•50m ago
The gate to the pig pen is closing…
ranger_danger•43m ago
Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops.

My ISP regularly changes everyone's IP, and I apparently share an ISP with people who suck, so I get flagged just trying to do all sorts of normal things. Some examples:

- I've never bought anything from Etsy but I'm somehow banned from even viewing their site at all.

- Discord immediately bans me any time I try to create an account.

- Can't buy flights from Delta, always gives a non-descript error.

- Can't buy concert tickets, it thinks I'm a fraudulent buyer.

- Most CF sites produce a "Sorry, you have been blocked" page, or just loop.

- Trying to buy products on a shopping cart will have my order silently flagged/canceled for "VPN usage" (I don't use one).

- Some sites/programs block me for being on the DroneBL or similar lists I did nothing to get onto, and have verified many times that it's not really coming from me.

I just take my business elsewhere... eventually I'll probably just stop using technology at all.

prism56•34m ago
Oh man I feel you. I turn my VPN off on certain sites due to the captcha loop.
Milpotel•16m ago
Wouldn't a 1£ Linux VM as Wireguard access point suffice?
coppsilgold•39m ago
My understanding is that this new reCAPTCHA is basically just remote attestation.

Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the Google server logs EK -> AIK conversions an attestation can be trivially traced to your device's EK. This is also why we don't really see and probably never will see online services which offer fake remote attestations, as it will be pretty obvious that the next step of running such a service is getting Google as a customer and having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.

Unless something special is done with this new reCAPTCHA not only are you locking internet services behind TPM chips but you are also surrendering anonymity to Google. Unless you acquire untraceable burners for every service, the new reCAPTCHA will be technically capable to tying all your accounts across all these services together. Much like age verification. It may appear that the service would need to cooperate to link the reCAPTCHA session to your registration but the registration time alone will likely be sufficient (the anonymity set will be all but destroyed).

ChrisArchitect•16m ago
Related:

Google Cloud fraud defense, the next evolution of reCAPTCHA

https://news.ycombinator.com/item?id=48039362

Google Cloud Fraud Defence is just WEI repackaged

https://news.ycombinator.com/item?id=48063199

kittikitti•13m ago
Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.

Camera Firmware Engineer, Consumer Devices

https://openai.com/careers/camera-firmware-engineer-consumer-devices-san-francisco/
1•haberdasher•22s ago•0 comments

Michael Burry: the market today feels like 'last months of the 1999-2000 bubble'

https://www.cnbc.com/2026/05/08/michael-burry-says-the-market-today-feels-like-the-last-months-of...
1•1vuio0pswjnm7•1m ago•1 comments

Pokegents: Making multi-agent coding feel like a team

https://castform.com/blog/pokegents/
4•kumama•3m ago•0 comments

Show HN: Agent-fox – write a spec, run agent-fox, and go do something else

https://github.com/agent-fox-dev/agent-fox
1•mickuehl•4m ago•0 comments

Practical Formal Verification for MLIR Programs

https://arxiv.org/abs/2605.01124
1•matt_d•6m ago•0 comments

Designing Microkernel IPC

https://seiya.me/blog/microkernel-ipc-design
1•birdculture•6m ago•0 comments

Discord Incident

https://discordstatus.com
1•moelf•7m ago•0 comments

Gemini 3.1 Flash-Lite is now generally available

https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-1-flash-lite-is-now-generally...
1•nateb2022•7m ago•0 comments

Digg Relaunches (Again)

https://di.gg/ai
1•qingcharles•9m ago•0 comments

How to Scale Your Model

https://jax-ml.github.io/scaling-book/
2•gmays•11m ago•0 comments

Meta's Embrace of A.I. Is Making Its Employees Miserable

https://www.nytimes.com/2026/05/08/technology/meta-ai-employees-miserable.html
2•1vuio0pswjnm7•11m ago•1 comments

Europe's quiet revolt against US cloud

https://willhackett.com/europe-revolt-against-us-cloud/
1•speckx•11m ago•0 comments

30 Points compliance check for redis generated by deep seek for Sparrow

https://chat.deepseek.com/share/9eakpdlaa6b88e38u3
1•melezhik•12m ago•1 comments

Someone vibe coded a dashboard for global energy flow

https://global-energy-flow.com/
1•ghoshbishakh•12m ago•0 comments

Remote Code Execution Vulnerability in Fooocus

https://mrbruh.com/fooocus/
2•MrBruh•13m ago•0 comments

Lets Encrypt Stopping Issuance for Potential Incident

https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
14•rbaudibert•13m ago•0 comments

Interpreting A/B Test Results: Statistical vs. Practical Significance

https://prepvector.substack.com/p/interpreting-ab-test-results-statistical
1•arnavashank19•13m ago•0 comments

Production engineering when trading billions of dollars a day [video]

https://www.youtube.com/watch?v=zR9PpXWsKFQ
2•abstrus•14m ago•0 comments

Roadside Attraction

https://theoffingmag.com/essay/roadside-attraction/
2•aways•16m ago•0 comments

Next

https://apps.apple.com/us/app/next-task-money-management/id6477492823
1•inkoda•18m ago•0 comments

You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)

https://ze3tar.github.io/post-zcrx.html
2•MrBruh•18m ago•1 comments

Show HN: Chat with UFO Files

3•freakynit•18m ago•2 comments

Guy Goma's Accidental BBC Interview Lives on After 20 Years

https://www.nytimes.com/2026/05/06/business/media/bbc-guy-goma-interview.html
2•nxobject•22m ago•0 comments

PayPal layoffs: New CEO cuts 20% of workforce in Q1 2026

https://qz.com/paypal-layoffs-ceo-turnaround-cost-cutting-050626
4•josephscott•23m ago•0 comments

My first in-prod corrupted hard drive problem

https://blog.pavementlink.ch/2026/05/07/my-first-corrupted-hard-drive-problem/
4•r1chk1t•23m ago•3 comments

Model Report, May 2026

https://www.oxen.ai/blog/oxens-model-report-may-8th-2026
4•eloyalbmartinez•26m ago•2 comments

Amazon's Durability

https://stratechery.com/2026/amazons-durability/
1•wslh•26m ago•0 comments

Jane Street Pulls in Record $16.1B Quarterly Trading Haul

https://www.bloomberg.com/news/articles/2026-05-08/jane-street-pulls-in-record-16-1-billion-quart...
3•petethomas•27m ago•0 comments

New PRNG, 3x faster than PCG64, more random, with secure version

https://mltechniques.com/2026/05/05/npg-new-random-generator-3x-faster-stronger-than-pcg64/
1•MLTechniques•28m ago•1 comments

Google A2ui to Prod

https://github.com/manupareekk/agent-ui-to-pr
3•manupareek•29m ago•0 comments