Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Eww. Ok, so, I’ve used reCAPTCHA on sites I maintain at work, just on forms to prevent excessive bot spam submissions. No way do I want to subject users to this BS, though. Does anyone have recommendations for other decent captchas that could be used instead?
  • hcaptcha is pretty popular these days. It uses a very wide variety of traditional visual puzzles.
  • Anubis is an alternative to captchas, it's OSS.
  • Bots are usually very stupid and will bail on any captcha system they don't recognize, so anything you make that's custom and requires javascript will cull 99% of them. This may change at some point with LLMs but for now my websites at least are still holding strong.
  • Cloudflare Turnstile, if you're already using Cloudflare (or not!): https://www.cloudflare.com/application-services/products/tur...
  • I run into https://www.hcaptcha.com/ and https://friendlycaptcha.com/ from time to time as a user without complaint. Can't speak to the latter but I've used the former a bit and it does the job.
  • I have a good friend who doesn't own a cell phone. He's a math professor. Every year he keeps living life without a smartphone, I continue to be more impressed. Things like this makes me feel like he might have to eventually give in. https://archive.is is now serving, via Cloudflare, this QR code backed CAPTCHAs. There seems no way to get past them without a smartphone. Sad times. I wonder at what point even basic government services will essentially require a smartphone.
  • I don't have one either. No plans to get one, even with this.
  • > https://archive.is is now serving, via Cloudflare

    It looks like a cloudflare page but it's not hosted by them. eg. https://bgp.he.net/dns/archive.is#_ipinfo It's hosted by AS49505 JSC Selectel

  • This isn't just about weirdos (like me) who run GrapheneOS. Huawei phones don't have Google Play services installed, or Xiaomi phones with MIUI China. That's what, a billion and a half phones that can't get to your website now?

    Amazon tablets don't have Google services either, which hints that the upcoming Amazon phones also might not work with this.

  • If you need access to both apps from China and websites/apps from outside China, non-Apple devices have been difficult before this, primarily due to push notification infrastructure.

    This makes it more difficult. But I don’t think it matters given how difficult it was prior to this.

  • This is crossing the line where the governments should step in and ban/fine google heavilly for this monopol behavior
  • Oh man as if we still live in those times
  • "Don't be evil. That's our job."
  • I agree. There are pretty clear grounds here to think about opening an investigation here into illegal tying, or a misuse of market power. Not sure if the FTC maintains a presence on here, but if you're listening...
  • Instead, our governments use this crap, meaning on .gov sites too, and impose it upon us.
  • The governments are the ones who needs the most. They want to know who all the potential and current dissidents are.
  • How you know this is a monopoly is that if you go on their documentation website half the video is how this rolls into Google Analytics.

    This is using another product to reinforce the search and ads monopoly.

    You can’t scrape content to build a better google or Gemini, you can’t make an OS to compete with Google or Apple, and you can’t make a Google Analytics competitor.

    It’s plain anti competitive.

  • I'm failing to see why they didn't just adopt Private Access Tokens (not that they're great either), where they could have at least:

    - pretended that it wasn't all about invading peoples' privacy.

    - done a good ol' fashioned "but Apple does it"

    - pretended to be standards-oriented

    - advertised it as something completely transparent to the end-user

    Seems like that would've caused a lot less backlash while still achieving the goal of having some form of device attestation -- but I'm guessing that's not the real goal.

  • The article mentions that they use Private Access Tokens on iOS, so I'm not sure where you're getting the idea that they're "not adopting" them from
  • Not Invented Here Syndrome?
  • "pretended" ... do they even care any more?
  • Private access tokens are also a repackaged WEI as far as I'm concerned.
  • It doesn't fundamentally solve anything. You want to be able to identify a specific person or at least a relatively expensive device so that if you ban them they stay banned.
  • I would love to see someone challenge this as an anti-trust violation. Google is using its market power (as the provider of reCAPTCHA) to actively prevent devices that don’t use Google Play Services from competing effectively.
  • They're only doing that because the EU currently doesn't want to antagonize US any more with their tech fines. Noticed how there hasn't been any as of recently?
  • It's worse than forcing the Play Services: strict Play Integrity requires your system to be signed by Google. So if you use the Play Services on GrapheneOS, you're still locked out.
  • I'm not sure the definition of anti-trust matches what you're saying. Are there any retail android devices for sale without Google Play Services? Also, notably iPhones will be able to still work despite not having Google Play Services.
  • It's a move to block competitor AI agents while securing access for your own, classic ladder kick. The market for autonomous agents providing services and doing online work will be gigantic so, unless you want your own bots locked out from ie properties guarded by Amazon, CloudFlare, Microsoft etc., you will need a bargaining chip.
  • As someone that uses AI agents, this makes me want to install a browser plugin for "public windows" that just archives everything I see, and then farms out clicks of content that are missing from those sites.

    The result of this would be to upload it all to a bot-friendly alternative to archive.org.