frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Google Broke reCAPTCHA for De-Googled Android Users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
50•anonymousiam•1h ago

Comments

hackernews682•1h ago
The gate to the pig pen is closing…
ranger_danger•54m ago
Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops.

My ISP regularly changes everyone's IP, and I apparently share an ISP with people who suck, so I get flagged just trying to do all sorts of normal things. Some examples:

- I've never bought anything from Etsy but I'm somehow banned from even viewing their site at all.

- Discord immediately bans me any time I try to create an account.

- Can't buy flights from Delta, always gives a non-descript error.

- Can't buy concert tickets, it thinks I'm a fraudulent buyer.

- Most CF sites produce a "Sorry, you have been blocked" page, or just loop.

- Trying to buy products on a shopping cart will have my order silently flagged/canceled for "VPN usage" (I don't use one).

- Some sites/programs block me for being on the DroneBL or similar lists I did nothing to get onto, and have verified many times that it's not really coming from me.

I just take my business elsewhere... eventually I'll probably just stop using technology at all.

prism56•44m ago
Oh man I feel you. I turn my VPN off on certain sites due to the captcha loop.
Milpotel•27m ago
Wouldn't a 1£ Linux VM as Wireguard access point suffice?
ranger_danger•10m ago
Nope, I have tried. Just as suspicious to them if not moreso because it's a datacenter IP and not residential. I even have a list of sites I've tried to visit that were explicitly blocked from datacenter IPs, and that file has over a hundred hosts in it now.
ck2•9m ago
whenever I can't access a website for various stupid blocks

I fire up cloudflare warp and walk right through it

use wireguard with wgcf in environments without cloudflare client

yeah it's stupid we have to do this in 2026 but I guess cloudflare is the new AOL garden

Jigsy•6m ago
> Sites that use reCAPTCHA/Turnstile/etc. have already been broken for me for years now due to neverending captcha/refresh loops.

I had this problem recently with the Indeed website. (Cloudflare Captcha)

Thanks to someone on Reddit, it was discovered that anyone using a Chromium based browser (Brave, Vivaldi, etc.) on Linux was being punished.

Awfully frustrating having to set up a Virtual Machine just to be able to access one website via Firefox since even my hardened Firefox was being punished.

coppsilgold•50m ago
My understanding is that this new reCAPTCHA is basically just remote attestation.

Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the Google server logs EK -> AIK conversions an attestation can be trivially traced to your device's EK. This is also why we don't really see and probably never will see online services which offer fake remote attestations, as it will be pretty obvious that the next step of running such a service is getting Google as a customer and having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.

Unless something special is done with this new reCAPTCHA not only are you locking internet services behind TPM chips but you are also surrendering anonymity to Google. Unless you acquire untraceable burners for every service, the new reCAPTCHA will be technically capable to tying all your accounts across all these services together. Much like age verification. It may appear that the service would need to cooperate to link the reCAPTCHA session to your registration but the registration time alone will likely be sufficient (the anonymity set will be all but destroyed).

ChrisArchitect•27m ago
Related:

Google Cloud fraud defense, the next evolution of reCAPTCHA

https://news.ycombinator.com/item?id=48039362

Google Cloud Fraud Defence is just WEI repackaged

https://news.ycombinator.com/item?id=48063199

kittikitti•24m ago
Please stop calling Android Linux. It's a marketing lie that continues to disappoint, including here. You're holding Linux back substantially by claiming Android is part of it. Just because it has Unix doesn't mean it's Linux as MacOS is also Unix.
prophesi•14m ago
Unless it was in a previous iteration of the submission's title, I don't see Linux mentioned anywhere.
PaulHoule•10m ago
The kernel is a Linux kernel. The userspace is very different from a typical Linux distribution.

Lets Encrypt Stopping Issuance for Potential Incident

https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3
59•rbaudibert•24m ago•17 comments

Google Cloud Fraud Defence is just WEI repackaged

https://privatecaptcha.com/blog/google-cloud-fraud-defence-wei/
523•ribtoks•6h ago•254 comments

AI Is Breaking Two Vulnerability Cultures

https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures
77•speckx•2h ago•27 comments

What we lost the last time code got cheap

https://www.poppastring.com/blog/what-we-lost-the-last-time-code-got-cheap
42•speckx•1h ago•23 comments

Cartoon Network Flash Games

https://www.webdesignmuseum.org/flash-game-exhibitions/cartoon-network-flash-games
177•willmeyers•3h ago•57 comments

Serving a website on a Raspberry Pi Zero running in RAM

https://btxx.org/posts/memory/
149•xngbuilds•4h ago•60 comments

An Introduction to Meshtastic

https://meshtastic.org/docs/introduction/
308•ColinWright•8h ago•116 comments

Bjarne Stroustrup: How do I deal with memory leaks? (2022)

https://www.stroustrup.com/bs_faq2.html#memory-leaks
52•theanonymousone•3h ago•35 comments

A web page that shows you everything the browser told it without asking

https://sinceyouarrived.world/taken
415•mwheelz•7h ago•207 comments

David Attenborough's 100th Birthday

https://www.bbc.com/news/articles/cp3pww9g0p5o
196•defrost•8h ago•21 comments

Show HN: GETadb.com – every GET request creates a DB

https://www.getadb.com/
10•nezaj•3h ago•1 comments

PC Engine CPU

https://jsgroth.dev/blog/posts/pc-engine-cpu/
96•ibobev•5h ago•39 comments

My first in-prod corrupted hard drive problem

https://blog.pavementlink.ch/2026/05/07/my-first-corrupted-hard-drive-problem/
4•r1chk1t•34m ago•5 comments

Google Broke reCAPTCHA for De-Googled Android Users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
57•anonymousiam•1h ago•12 comments

Rumors of my death are slightly exaggerated

1250•CliffStoll•2d ago•195 comments

Cloudflare to cut about 20% of its workforce

https://www.reuters.com/business/world-at-work/cloudflare-cut-over-1100-jobs-2026-05-07/
1224•PriorityLeft•23h ago•866 comments

Apple, Intel have reached preliminary chip-making deal

https://www.reuters.com/business/apple-intel-have-reached-preliminary-chip-making-deal-wsj-report...
129•scrlk•2h ago•69 comments

Poland is now among the 20 largest economies

https://apnews.com/article/poland-economy-growth-g20-gdp-26fe06e120398410f8d773ba5661e7aa
782•surprisetalk•7h ago•669 comments

Mojo 1.0 Beta

https://mojolang.org/
199•sbt567•17h ago•139 comments

US Government releases first batch of UAP documents and videos

https://www.war.gov/UFO/
164•david-gpu•7h ago•257 comments

Canvas online again as ShinyHunters threatens to leak schools’ data

https://www.theverge.com/tech/926458/canvas-shinyhunters-breach
885•stefanpie•21h ago•589 comments

You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)

https://ze3tar.github.io/post-zcrx.html
4•MrBruh•29m ago•1 comments

pg_flight_recorder: Continuously sample PostgreSQL system state via pg_cron

https://github.com/dventimisupabase/pg_flight_recorder
6•tanelpoder•1d ago•0 comments

Maybe you shouldn't install new software for a bit

https://xeiaso.net/blog/2026/abstain-from-install/
790•psxuaw•21h ago•410 comments

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
95•ggpsv•6h ago•20 comments

Ask HN: We just had an actual UUID v4 collision...

208•mittermayr•12h ago•195 comments

GeoJSON

https://geojson.org/
131•tosh•10h ago•64 comments

Show HN: Git for AI Agents

https://github.com/regent-vcs/re_gent
72•doshay•5h ago•42 comments

Dirtyfrag: Universal Linux LPE

https://www.openwall.com/lists/oss-security/2026/05/07/8
768•flipped•1d ago•308 comments

Defeating Works by Design's Unpickable Lock [video]

https://www.youtube.com/watch?v=rMi1dIqMwNw
12•zdw•2d ago•4 comments