• Google is making it mandatory to have Play Services for its next-generation reCAPTCHA system on Android.

  • Your phone will need to be running Play Services version 25.41.30 or greater when the system asks you to scan a QR code for verification.

  • This hurdle means that de-Googled phones will fail the verification test by default.

  • 9tr6gyp3@lemmy.world
    link
    fedilink
    English
    arrow-up
    134
    ·
    24 days ago

    If you’re a web dev, and you implement this, just know you won’t receive my web traffic. Ill go live with the other robots and we will start our own internet with blackjack and hookers.

      • akwd169@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        23 days ago

        Lemmy know when you do and how it is in a cabin in the woods in Northern Canada because, as a Canadian, thats what im doing if I drop the web

        Eta: we can use meshtastic to communicate

    • arcine@jlai.lu
      link
      fedilink
      English
      arrow-up
      7
      ·
      23 days ago

      This goes well with another thing I say : “If your website only works on Chrome, your website doesn’t work

  • Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    91
    ·
    24 days ago

    That means if Google’s verification system gets widely adopted, browsing the web could become a headache.

    Using a phone to scan a QR code in order to access a website on my desktop is a headache even if it has no dependencies in particular.

    • limonfiesta@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      24 days ago

      Unless it was the website I needed inorder to receive an organ donation, I would just close it.

      I could claim that’s an act of righteous protest, but really I just know that absent my needing a new liver, there’s no website I would ever care enough about to get me to scan a QR code just to keep browsing.

  • Wispy2891@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    ·
    24 days ago

    This is awesome news for scammers:

    1. Fake page will say “you need to scan this qr code to verify you’re human”
    2. Users normally dismisses this shit, but it has become normal nowadays, take out the phone to scan it
    3. Qr code opens a page on totallynotascam.com that say “you need to install this totally safe APK on your device for verification 😉”
    4. APK passes the new useless developer “verification” as the scammer either used a hacked dev account or just paid $25 with a stolen id + stolen credit card
    5. User see the message “APK verified by Google play protect” and would totally believe the bullshit, giving all the possible permissions to the app
  • thejml@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    52
    ·
    24 days ago

    Ignoring the de-Googled phones for a sec: I assume if you’re using a desktop, then the QR shows up and you have to drag out your phone to scan it in the camera app that then prompts to open the google play store. Dumb, but possible for people who have a phone with Android. What about those that don’t? Would you need a google account?

    Now if it’s all on phone (using Chrome or Firefox or whatever) and pops up a QR code, you can’t scan it… but the browser would have to open the play store directly and thats a huge security no-no. The browser shouldn’t even know I have the Play Store.

    I have a feeling the hundreds of us that are de-Googled ad just going to stop using these sites all together.

    • Phoenixz@lemmy.ca
      link
      fedilink
      English
      arrow-up
      22
      arrow-down
      1
      ·
      24 days ago

      Yeah, so the hundreds of us won’t be able to use the internet anymore if this passes

      Awesome

    • timestatic@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      24 days ago

      What about people who use iPhones? Even if I used a normal google android I wouldn’t want to be bothered to scan a qr code with my phone to verify myself every time

  • x00z@lemmy.world
    link
    fedilink
    English
    arrow-up
    39
    ·
    23 days ago

    A lot of Android bot devices simulate (or even ARE) a full phone with a legit Play Store and other Google services.

    This requirement is enforced vendor lock in. Nothing more.

  • Phoenixz@lemmy.ca
    link
    fedilink
    English
    arrow-up
    31
    ·
    24 days ago

    Once this is implemented, Google will have finally succeeded in closing the entire fucking internet. That is, assuming this will become anywhere successful and smaller websites will be using it as well.

  • ennof@feddit.org
    link
    fedilink
    English
    arrow-up
    29
    ·
    24 days ago

    “Google’s next-gen reCAPTCHA system could spell trouble for any website that implements it as no de-Googled phone user will care to use it”

  • MuteDog@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    23 days ago

    This requirement will kick in the moment the system suspects suspicious activity. At that point, reCAPTCHA will forgo the old image puzzles and require you to scan a QR code with your smartphone to prove you’re human.

    How is this going to work if you’re browsing the internet on your phone??

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      23 days ago

      How is this going to work if you’re browsing the internet on your phone??

      Easy, they force you to install an app, just click the link and agree to all the permissions and cookies and stuff. It might be malware, it might be legit, who knows?

      official Google screenshot

      Google copying UI workflows from literal malware developers…

  • Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    24 days ago

    This is evil. Fuck it. I want nothing to do with these cunts anymore. I’m degoogling this year.

  • PierceTheBubble@lemmy.ml
    link
    fedilink
    English
    arrow-up
    20
    ·
    edit-2
    24 days ago

    It turns out reCAPCHA has been a privacy nightmare from the beginning: from silently monitoring user activity in the background, to sending payment information to Google; in order for an AI to assess the data, and return a risk-score to the website. But that apparently wasn’t bold enough, and now an effective 2FA is required, which provides additional telemetry to Google (but not to the website or app: which is obviously the privacy concern). So get ready to 2FA with Google upon registration, login, updating your cart, and payment; or to skip the hassle, you should just let an approved “shopping assistant” make purchases for you (“that drive a projected 25% increase in average order value”). I don’t even own a modern Android or iOS device, so how am I supposed to solve these?

  • Blue@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    24 days ago

    Then I’ll just not use the services that use it, very stupid, as this shouldn’t be necessary

    • matlag@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      23 days ago

      We’ll talk about that again when all banks, online reservation, government websites all require the new captcha.

      Oh, but you can still join us by phone to talk to an AI agent or wait forr 240mins of average waiting time for a human operator.

      • Wispy2891@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        23 days ago

        Banks love to reinvent the wheel and definitely can’t trust Google to be part of their workflow, as Google will 100% change UI or steps or rename the app or discontinue the app while replacing it with an identical one but with a different name but less features with no advance notice. Relying on Google for banking workflow means that one day the bank user support will be overwhelmed by requests like “the button disappeared, where is it now”

        For the rest of stuff, this system IMHO has too much friction, the bounce rate will be too high. Businesses won’t like to pay for a bot detection system (it costs $1 per 1000 verifications) that will push humans away while bots pass it without problems (either by using the accessibility workaround or by using those smartphone farms in southeast Asia)

    • wabafee@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      23 days ago

      Even worst there is a huge privacy concern here. Google would associate who’s browsing anonymously in desktop with their phones which Google has more access on your information. It is already a privacy concern before but at that time they go in a roundabout way, today we just give them the platter.

  • Phoenixz@lemmy.ca
    link
    fedilink
    English
    arrow-up
    17
    ·
    24 days ago

    Monopoly, anybody?

    Naaaahhh, this is just good old fashioned American freedoms

  • systemglitch@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    23 days ago

    I’ve scanned 4 QR codes in my life. 2 were not what I was told they would be.

    I will never scan a QR code again.