graphene can have the play service, but in a sandbox. anything other than that uses microg so its emulated. probably needs some time to get up to speed. if not, just use the desktop site instead of mobile. i dont really see this as much of a threat to any of us.
Desktop site is going to require QR scan.
I don’t know what they are going to do about “I don’t have a phone” / “I only have a dumb phone” population. I suspect that sometime soon I’ll have to buy a stay-at-home Google certified device, to bridge the locked down features and services.this is such a weird idea to me. why do i need a phone to browse on my pc? what if my phone is not charged, what if the camera is broken or simply covered due to work regulations. such a dumbass idea.
Pretty sure their solution would be mandatory carrying of approved devices. It will be the only way to provide identification and payments, essentially all the stuff religious nuts say about the mark of the beast minus the weird parts like demons or the invisible counter mark and shit like that.
It is true that it’s impossible to buy things or identify yourself online right now, so I can see why they’re doing it.
Most 2FA solutions on commercial websites (bank, online payment, electricity/water/gas providers) require a phone here instead of using open standard solutions or using physical tokens. They are doing everything they can to force us in to a Google/Apple lock in.
They don’t give a shit about that part of the population, maybe they can even force some of that part of the population to finally cave in and get a smartphone.
For a decade or two now, it’s been pretty much assumed that everyone has an internet-connected, camera-equipped, browser-capable device in their pocket. Restaurants, banks, hospitals, employers and even government offices use QR codes and websites to get you to their menus, forms or services.
If ID is being tied to my mobile spy device, then I need my mobile spy device to be a right and not a luxury. $40-50 for a few years of validity, internet access provided at no cost, even if slow. I can have my luxury phone be where I’m ‘anonymous’, but I want the government to subsidize the mobile spy device if it’s a mandatory expense. Even cheap phones cost a lot of money.
To be clear, I don’t want ID tied to my phone, but it’s gotten harder to exist without one, so it should be something we have access to with minimal friction.
Add food, water and shelter to that list, but you can’t ask for them without a web browser.
You can install Google Play Services as a sandboxed app on GrapheneOS. That’s not the issue. I believe the issue is that Google will use hardware attestation to check if the OS you’re running it on is Google-approved.
Most of the time, my phone’s browser is disabled. It keeps me from using my phone too much. I understand not everyone is in a position where they can do that though.
i have one myself, and I can tell you that grapheneos won’t be affected by this. the real damage is to people using things like dumb phones or BSD, even windows computers are effectively locked out of the internet.
Sounds like GrapheneOS isn’t affected only for now?
As in sandboxed google play may stop working for this at any point.
;(
that’s true, things can change at any point. hopefully a workaround is found if it ever gets to that point though. them sandboxing Google play was impressive in itself.
Apple and Google are gradually expanding their use of hardware-based attestation. They’re convincing a growing number of services to adopt it. Google’s Play Integrity API and Apple’s App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.
Google’s Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition.
The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it.
Apple’s Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web.
Google’s reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems:
er/16609652
Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple’s privacy pass, Google’s ‘cancelled’ Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web.
Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They’re bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more.
Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It’s enormously anti-competitive.
Google’s Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn’t somehow specific to an AOSP-based OS. You can’t avoid this by using a mobile OS based on FreeBSD instead. You’ll just be more locked out.
Google’s Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it.
It doesn’t provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source.
Governments are increasingly mandating using Apple’s App Attest and Google’s Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them.
Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they’re directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security.
reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that.
This isn’t about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don’t license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere.
Services shouldn’t ban people from using arbitrary hardware and operating systems in the first place. Google’s security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It’s for enforcing their monopolies via GMS licensing, that’s all.
well, I guess i will stop using those websites from my /e/os fairphone
And nothing of value was lost. I’m over social media, over commercial apps, and maybe I’m over having a mobile phone, too.
That would make the two of us. My Fairphone 3+ is still kicking well with /e/OS.
What they are doing is way worse tban what you understood.
These QR codes will show on your Desktop PC and you will need an Android phone or an iOS device with a logged in Google QR code app to get past it.
Is it bad I use this for steam login? I thought that was secure …
I am in no way condoning Google’s behavior, nor am I trying to normalize it. With that out of the way: maybe running Android Studio with an AVD might be a decent workaround. For now…
I wouldn’t scan shit from a website. Random QR codes are a security risk. Just won’t visit that website.
That’s why you have to use the special google app that will protect you from all these dangers*
*and also collect all your data, sell it to advertisers and forward it to US surveillance agencies (for your own protection of course).
Sad thing is, that argument works against so many ppl. “I can trust this app. It’s from Google!”
We(*) are tearing down personal computing. Brick by brick. The very idea of controling our own devs is getting lost. Replacing with Big Tech Feudalism.
(*) Not most of us here. But in the whole pop.
so they are not only tracking you, but they are trying to reconnect your records across multiple devices.
Ayup that has been the holy grail of big tech.
They are most of the way there today. Make Identity Resolution inescapable. Bing bang boom.
It is more than just phones and lappys too. It’s everything. That smart TV. That fitness watch. That automobile. That streaming music service. The ebook reader you got as a birthday gift.
Your behavior across every single device is data gold. This is today’s reality.
Yep, data gold to sell to data brokers and investors so they can sell you shit that you don’t need and can’t even afford.
And through the VPN
Guess I’m not going to Youtube, then.
I see a future where we have our mandated government ID shitphone for banking, corpo and government suchn’shit, and the laptop we access Anna’s, Yggdrasil and TOR with.
and the days go by!
Not exactly same as it ever was, but seems kinda 2007 to me. I doubt any Lemmy instance or i2p site will enforce Google’s QRcode spy-proxy.
My current GraphineOS phone will probably be my last smartphone. I’ll be moving to a dumb phone and a data hotspot connected to some type of cyberdeck. Will have that thing locked down, blocking known abusive companies like Google. Honestly could care less about using any service that touches them.
It’s not 2007. Devices are everywhere now, smartphones, TV’s etc. The social dimension (social pressure) and implications are very different now. Their power increases, amount of people caught in the loop is immense now. 2007 was all still fun and games.
Undoubtedly, and more still will be as corporate greed turns the internet into pay-per-view TV. We can’t help that.
Make your decision for yourself for what to do with your connections and your own devices. You are in control of at least that, if nothing else.
Can we trust that isn’t a campaign to promote Google? What are these websites? Why aren’t they blocking an iPhone? Can any of that be replicated or is this just a Google campaign to create fear and doubt
Its basically forced by Google. I mean who wouldn’t force it after someone deliberately removes your government sanctioned spyware. See if people stopped calling it google or Apple and just USA spyware with backdoor to your lives it would be better at getting to the privacy issues. I mean the NSA already proved this is a fact.
Yeah exactly. Millions of websites? Which ones? Though I don’t see how this would benefit google
Haven’t encountered this yet, has it been let loose in the wild?
GrapheneOS user here! Not sure about websites but there are certain apps that don’t work properly without Google Play Services, but Graphene’s app store has a sandboxed version of it, so I just installed that and revoked all it’s permissions. Then if an app needs it, I just turn on the relevant permission, do the thing and then turn permissions off again. It’s a bit of a pain at first but I’m used to it now.
Note that some apps will say that they won’t work without GPS, but actually will if you give it a try.
some of them are now straight up refusing to run without the play store.
Then they don’t deserve your business
Man, I want a phone with physical kill switches for things like Wifi, GPS, Bluetooth, because a lot of things seem to detect when these things are turned ‘off’ by software. Wonder how they’d react if in software, GPS is enabled, but the actual hardware is not powered at all
They most likely won’t work. Just speculation, but I would imagine most software that “needs” information like GPS don’t care that its on or off, they care that they try to pull data and there is none.
pine phone
I’m a grapheneOS user and I don’t have any google services installed. I havecyetvto hit any major issues with any apps or websites I use. Lucky, maybe?
The main ones for me are the RBC app, Skip the Dishes and Communauto. But I think those might all be Canadian?
I’d say making a 2nd user for the apps that need Play Services (like banking and Uber/Lyft) is the move. This only allows Play Services to run when the 2nd user is on and also fully seperates it from the main user!
Oh yeah that’s something I’ve been meaning to look into!
Because the iPhone has their own spyware to prove you’re a
productuser.
https://support.google.com/recaptcha/answer/16609652?hl=en
https://blog.cloudflare.com/how-to-enable-private-access-tokens-in-ios-16-and-stop-seeing-captchas/Interesting. Definitely turning that off. (As if it actually turns off)
If you turn it off, you’ll have to do the captchas manually.
Yeah I’m okay with that.
I just do them wrong, after a few tries it lets me through
Good point, this would have to work on iPhones too and people without a phone would just not be able to use those websites at all.
I just loaded a bunch of recaptcha on my GrapheneOS phone. So, I dunno what this is all about.
All these captchas just make me evaluate effort vs need. Facebook throws a captcha every time because I log in from a private window. Before it just gave me a warning unrelated to my interests. I mostly use facebook for work, and those sweet lawnmowing videos. If they keep it up I will only log in for work.
Last time I attempted to log into Facebook it gave me a captcha where it wanted me to select which stone pillar had x number of stones in an AI generated photo. I could never get it right, so I cut my losses and have not gone back.
This is really bad even just from the perspective of user behavior. Training people to scan QR codes from anything that looks like a captcha box is HORRIBLE for security.
“Thanks for scanning the code, just one more step! Please input your phone number, and type in the code you receive.”
Boom, account stolen.
It’s almost like they don’t really care about your security…
And the phone number thing is already happening too. Google, discord and probably other stuff already ask for a phone number to prove you are a human when they flag your account.
It’s a server setting. one of my oldest servers has enabled this and I haven’t chatted with anyone there anymore because I need to verify my phone first.
This does seem to work with sandboxed Google Play Services on GrapheneOS btw.
I scanned the demo QR code on Google’s talk page about it with sandboxed Play Services enabled and it gave me a custom popup asking if I’d like to verify.
and you can do it from a second profile which contains none of your data.
Unless you’re doing that from a separate device in a separate location then all you’re doing is giving them the data they need to link those two accounts
You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.
Sandboxed Google Play Services doesn’t have privileged access to location information, so it can’t pull your GPS location or Wifi Positioning information. It would only see a blank profile and doing this would allow for your primary profile to continue to not run Play Services.
Any malicious code which could be injected into the process would find itself in a sandbox, on a blank profile and isolated from the rest of the system.
Google would only see that you are authenticating from a profile without anything installed, from an unknown location and coming from whatever VPN endpoint that you’d like. They could possibly infer that the blank profile and your ‘real’ profile are different via browser fingerprinting. You can randomize a lot of fingerprinting datapoints with browser extensions, but avoiding browser fingerprinting is a whole other topic.
The ‘real’ privacy solution is to avoid anything that uses this version of recaptcha. However, if you have to use these services then you can still reduce the amount of information leaked via Play Services by using a blank profile to scan the QR codes.
You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.
its not even about complete anonymity. google has zero business in when I’m logging into my utilities company account, or other semi-governmental portals!
it literally is their business; they make millions of dollars off of it.
then that’s a problem we must solve. Because an adtech company should definitely not have any business in that.
it has been solved for approximately 2 billion people on this planet, but those answers are not friendly to profit-seeking institutions like google and the only remaining institutions that can stop it are captured by the likes of google
That’s assuming they know I have another account
how is ubuntu touch or kde touch going? when i switch to my next phone Android might be a no go
ubuntu touch works well but there’s almost no apps for it. there’s not even firefox
Kde mobile…exists. It’s even possible to run it. I wouldn’t expect an amazing performance though.
I don’t use the internet for much these days, but I am on graphine OS and I have yet to be blocked from websites due to it. My adblocker prevents me from some, and not allowing javascript prevents me from some, but I’ve never seen that QR code or had any site prompt fro Google play services
this seems too new to be widespread yet
Right? Google is extremely well known for its A/B testing.
I doubt OP cares, but I use GrapheneOS with Google Play services. It’s still better than regular Android. Don’t give up because you can’t get 100%
I would imagine that having a full control of the underlaying system would allow a wrapper to be developed for the Play Services, so it would not to be able to spy on you so well. Just feeding some partially spoofed data to it, or even whitelist it to work only with the apps that require it.
That’s exactly what the GraphendOS project did. IF you choose to install Google’s bullshit, which I did to use Maps and such, they run in a wrapper that makes them usable without the level of system access they typically require.
I had one of these CAPTCHAs recently and it still gave me the option to verify by clicking the squares. I wouldn’t be surprised if they phased out the ‘legacy’ verification though.
closing the tab works better
Let’s hope the EU prevents this from happening. We should be able to access every site we wish without Google’s permission.
The EU is busily building the Fourth Reich so don’t expect help from there.
Please elaborate.
Yeah, sure, at a really slower pace than USA. Maybe in a century. They still care more for their citizens Trump ever did.
LOL, whatever you’re taking, stop, it’s doing your brain in! :D
The ongoing battle against online privacy is a symptom of capitalism, the EU is a capitalist state. The only thing the EU would ever do against US-based capitalism is to gobble up those capital gains for themselves. It doesn’t matter if it happes or not, the privacy-issues for end-users would never be alleviated by the EU.
From what you’re saying, they would’ve already introduced all those capitalist methods of control the first time around.
Which they didn’t.
What gives?
Also: the EU is literally incapable of “gobbling up capital gains for themselves” because “themselves” doesn’t exist in this context - the EU is not a “State”. The member-states might (and some do).
I see you have no clue. You will learn, eventually.
Go ahead, teach me.
We should all be encouraging Europeans to:
- Force Android and iOS to be given to the people to own and open-source the OS fully in EU with GPL license
- Fine them to oblivion if they do not cooperate
- If they try to double down then piece up their companies into parts
We all tired of their fucking shit. Everyone keep getting people active and informed on all this!! Together anything is possible!!





















