cross-posted from: https://lemmy.ml/post/47972724
i encountered this for the first time today while attempting to read something on archive.today.
i confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.
the old type of captcha remains available too, for now:
-
People without a mobile device are fucked out of being able to pass a captcha
-
As if this isn’t a way for them to associate multiple sessions on multiple specific devices with one another, this is just another avenue for data collection, period. Hidden under the guise of “more secure.”
I imagine scammers are already thinking of ways to use this for phishing too
deleted by creator
not if you kill google first
deleted by creator
🟩 🧑🔧 🪠
The point with captchas is not really that bots can’t pass them, more that its too expensive to pass them consistently with a hurtfully large enough volume of bots.
I’d heard of this strategy, like making it perform some kind of costly encryption that’s irrelevant to a human user but restrictively expensive for a bot army.
But does decoding a QR code apply? I never really thought about it. I guess it’s an image, it’s at least a little big by comparison… but it’s also in a restricted, easy to capture spot and maybe could be minimized to a fairly small pixel set? Idk how many key pixels you need to parse a QR code… I guess I could Google
*typo bit --> bot and bit --> big… I’m full of bit
Since a QR code is just made of squares, it can be very, very tiny
1 square = 1 pixel
I don’t know much about this new captcha system, but I feel like the challenge wouldn’t really be in the scanning of the qr code itself but more so on making the device you’re scanning with seem legitimate. They could check usage patterns, what apps are installed, how many accounts are added and are they actively used, location and sensor data, are the hardware specifications really unusual, are they constantly trying to complete random captchas… Stuff like that to tell apart a real user’s device from a bot or sandbox. The QR Code is probably just a random ID for which captcha instance the user is trying to pass.
Also I just realised this but this is probably inconvenient as hell. Like I do NOT want to constantly be picking up my phone to scan QR codes when I’m trying to go around the Internet. What if my phone is on the other side of the house? I don’t want to get up and walk all the way over there! If this gets fully rolled out there may actually be a small dip on the amount of desktop users of websites because they just leave when they are hit wth this captcha instead of bothering to scan a code.
Captcha has been one of the greatest google acquisitions ever.
They acquired it under the guise of improving OCR and have since morphed it into an AI data farm (how else is google lens gonna know what objects are what?) and now total insight into a users every single action from desktop to mobile, tying it all together into a surveillance nightmare.
I can guess the permissions that the recaptcha app needs now. Probably something akin to root access with all datapoints and considerations you could think of.
How would that teach Lens to recognise anything other than motorcycles and traffic lights really well?
I’ve had many, many not traffic light and motorcycle/bicycle recaptchas. They’re probably leaning a bit into self driving learning the past few years.
Lens has a lot more data points nowadays after everyone’s google photos was used for training for what, 10+ years at this point?
Google harvested all human typed words 15 years ago with the google library project. They’ve been hoarding and processing data for models forever.
I used to always add one incorrect tile and skip one correct tile.(It would still pass)
I thiught I was such a rebel lol
Then I figured, they’d be stupid if they didn’t show the same image to multiple people…
You don’t have to drink a verification can, but you do need to buy a verification phone.
i have one. but it isn’t android, or ios, or ‘smart’ in any way. it doesn’t even text. it’s just a telephone that fits in my pocket and connects to the cellular networks. it’s all i want. it’s all i use. it’s all i’ve needed ever since i got my first one about 25 years ago.
Same! Except mine does do SMS text and has the other flip phone stuff like alarms, timer, calendar.
Don’t worry you’re included. Simply visit one of our Accessibility Centers between 8am-9am on odd Wednesdays, with a valid birth certificate, filled-out form from here, and a notarized Charizard.
It really should be illegal to build systems that require a user’s access to any unrelated technology. You shouldn’t be forced to have a phone to pay a parking fee or to get on the bus. You shouldn’t need an app to charge your car. You shouldn’t need to use proprietary software from one spesific company to pass a captcha on a random site.
I mostly use my phone (Pixel with GrapheneOS) as a dumb phone + calendar. But by far the biggest number of apps I have to have on it are the fucking car charger apps.
-
deleted by creator
This is the only way to stop it. We must refuse to use it. All they watch is the numbers.
I bought a thing from Walmart using pickup for the first time, because the thing was “low stock”, and I didn’t want to drive there if they didn’t have it. I get the email that it’s ready, and they want me to download their stupid app to confirm. Fuck that, I went to the store, knowing I had a backup option, and found the last one of the thing on the shelf and bought that instead. Although, apparently the sign at the parking spot has a phone number you can call to let them know you’ve arrived–no mention of that option in the email.
That’s it. JavaScript was a mistake. Time to go back to HTML only pages
obligatory NoScript advertisement
This? This is the JavaScript straw that broke your back?
Are you implying that Spice Hoarder is a camel?
I can neither confirm nor deny these claims
I meanf you can do this flow without JavaScript: The server renders a QR code and sends it in a static web page and on Android, you register a URL handler to do the rest of the flow.
Absolutely not
There’s no way this is ADA compliant.
With the way the Trump admin is going I’m surprised they haven’t totally dismantled the ADA already.
Clicking the headphone icon to hear the audio option is the way to bypass this if you get one.
For now, yes.
Although having tried to use the audio recaptca before, it felt like a psychotic episode.
Yes, I don’t use them regularly but the audio captchas don’t have a good reputation among blind users.
Be prepared for an audio qr code that requires a special app to decode
to prove you’re human, enter your credit card number
your pin, cvv and expiry date too, which confirms you are actually human
If you haven’t already divested from Google and its related services then now is the time.
deleted by creator
Not if this abuse finally succeeds in driving away other peoples’ customers. Captcha losing people money makes captcha go bye bye
deleted by creator
Without a google account there will be many sites I can’t visit. I’ll look at such sites the same way as I look at paywalled sites.
It is a paywall, you just pay with your data. Except Google gets the revenue and not the website so maybe a second paywall will be “necessary”
Nah. Block all fingerprinting. You don’t need any of this crap.
what do the Visual 👁 and Audio 🎧 options look like?
The visual option is the normal reCAPTCHA (eg) and the audio option is the (quite difficult) thing they’ve been subjecting blind people to for years. Presumably they will keep offering desktop users these options (at least in many/most cases) for a long time still; this new phone-required extra-invasive CAPTCHA is just a hint of where they’re heading. (But already it is apparently actually required for Android users in some cases: https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users …)
I bet this will be removed soon.
if the old ways are still available, the bad guys can use 'em too… so this new thing is just to get people ‘used to’ the idea of an anal probe for verification before actually forcing it on everyone.
This is going to work just amazingly well with AI moderation, faceborg style.
I got one of these. They had accessibility options so I just did the auditory one. It says a couple words, you write them out, and you’re done. Like hell am I using a Phone for this shit.
FWIW I’ve found passing it through my local SearxNG usually gives me a clean path to the content. But it’s seriously worrying that some of the blocked content is publically available science (e.g. PMC Bioinformatics). But that should not be necessary, at this point a search engine should be a public resource. Fuck Google.
I still won’t order online from a store that won’t show me shipping cost without a full address and phone number. I’ll give them the zip code, that’s all they need, that’s all they get before I decide.
I know it has been said already but how stupid is it to teach users the pattern of randomly scanning QR codes. So ironic given that reCaptcha is for security in some sense.
It’s the same with ID verification. For your safety you need to start giving random websites your drivers license or passport…
I had a site I was gunna buy stuff from ask me for a video selfie to “prove” I was over 21.
First if all, I wasn’t buying anything controlled, so thats ridiculous over-reach, and second of all LOL FUCK NO I’m not giving you, some random-ass e-commerce site, my fucking biometric data. That’s absolutely insane.
Needless to say, I blocked that site on my pihole, so it no longer exists to me as an option. Sent them a message letting them know they lost a rather substantial sale from that shit. I’ll do that for absolutely every one, same with ID or whatever else. I could just use the tricks kids use, but that still rewards them for this bullshit with money.
I’ll just stop using the internet if it becomes a thing everywhere. It’s not really worth being on anymore, for the most part, anyway.
I don’t blame you. Personally I get more satisfaction from using fake IDs or directing a video selfie thing to a video game character etc or finding some obscure bypass to whatever bullshit they throw at me. That way I still get what I want from the website and they get nothing of value from me, lmao.
Can you explain me how i can direct the selfie thing to a image i have on my computer? I didn’t found anything and ya seem to know something
It’s called the boiling frog effect.
It’s not for your security :(((
It’s the same with ID verification. For your safety, you need to start giving random websites your drivers license or passport…






















