The ways in which Google can lock you into their ecosystem are often obvious, but sometimes, they’re incredibly sneaky and easily missed.
CAPTCHA tests are annoying, but at the same time, they can help protect websites from bots. While these tests are already the bane of our internet existence, they are going to get worse for some Android users. A requirement for Google’s next-generation reCAPTCHA system will make it a lot harder for de-Googled phones to browse the web.
A Reddit user has highlighted a seemingly innocuous support page for Google’s reCAPTCHA system. The page in question relates to troubleshooting reCAPTCHA verification on mobile. In the document, it says that you’ll need to use a compatible mobile device to complete verification. If you have an Android phone, then that means you’ll need to be running Google Play Services version 25.41.30 or higher.
↫ Ryan McNeal at Android Authority
When was the last time you actively thought about reCAPTCHA being a Google property? Even then, when was the last time you imagined something as annoying but ultimately basic as a captcha prompt could be used to tie people to Google Play Services, and thus to “blessed” Android? Every time we manage to work around one of these asinine ties to Google Play Services, another one pops up to ruin our day. We’re so stupidly tied down to and entirely dependent on two very mid – at best – mobile operating systems, and it’s such a stupid own goal for especially everyone outside of the US to just sit there and do nothing about it.
Worse yet, it seems we’re only tying ourselves down further, while paying for the privilege.
At the very least we should be categorising certain services – government ID services, payment services, popular messaging platforms, and a few more – as vital infrastructure, and legally mandate these services have clearly defined and well-documented APIs so anyone is free to make alternative clients. The fact that many people are tied to either iOS or “blessed” Android because of something as stupid as what bank they use or the level of incompetency of their government ID service should be a major crisis in any country that isn’t the US.
I don’t want to use iOS or Android, but nobody is leaving me any choice. It’s infuriating.

> I don’t want to use iOS or Android, but nobody is leaving me any choice. It’s infuriating.
That’s the plan. If you look at US BigTech as an extension of the state’s surveillance and spying mechanism, everything makes sense.
Even worse, Thom is in sweden and they are not only shutting down the use of GSM/2g/3g and some 4g networks. They are actively saying what phones models and brands can be used on the 4g VoLTE and 5g networks. Comviq for example lists no phone under 11k SEK as compatible, and every jailbreaked phone running sailfishos or lineageos is now a brick on all operators other than telia which will let them operate until 30th dec of this year beforethey also shut them out.
NaGERST,
ATT did the same in the US, on the 5G transition ATT’s own phones were whitelisted to continue being supported, it was other phones that got denied service even though they used the same technology.
IIRC the carrier terms for wireless spectrum changed between 4G & 5G. Carrier discrimination against phone models used to be prohibited, and is now allowed.
Unfortunately once the government steps in they will make their own version of Google Play Integrity so they can enforce any draconian law they can think of.
Out of perverted curiosity, how did they even accomplish this? I mean, there is nothing in HTML, CSS, or JavaScript that is Play Services-specific. Does Chrome for Android offer a secret orifice to some proprietary Play Services API just for reCAPTCHA?
Also, can’t de-Googled Android phones just pretend to be iPhones?
As an aside, it’s funny seeing Eurocrats talk about “IT sovereignty” while member states (and major banks regulated by said member states) require the use of Android apps that require Play Services.
Judging by the content of the linked article. It’s saying that their “next-generation reCAPTCHA” will require people on desktop PCs to scan an on-screen QR code with their mobile phone to prove they’re human.
It’ll be interesting to see how much pushback they get on that.
ssokolow (Hey, OSNews, U2F/WebAuthn is broken on Firefox!),
Not only that, but it seems like it will primarily harm humans. Bots can open up QR codes easier than humans can.
If I place a tin foil hat on, I might even say such a feature is just a clever cover for an alternate agenda, the real purpose being to improve google’s tracking of users across devices.
That’s not tinfoil hat at all. In fact, tracking users across devices, services, and everything else is exactly their intention. They want to know everything at all times, and I’m not even being funny.
Ughhh… this sounds worse than even the headline suggests, and not just for de-Googled Android users. In my case, after many years of hassling with ad-hoc unofficial Android ROMs, I eventually decided to just own an unmodified cheap Android phone that works with a few banking apps I occasionally need to use. But I treat my phone as a necessary evil, using it only when absolutely needed, and the rest of the time it sits there with the internet disabled. Mobile devices can and *do* get lost and stolen and broken much more frequently than a real computer, and I absolutely *hate* accounts and services that depend on a phone and/or mobile phone number (also ephemeral in my case). What I really depend on day in and day out is my real computer running Linux. So requiring a phone at all (whether de-Googled or not) for CAPTCHA verification on the desktop would be hugely disruptive to my workflow, to say nothing of privacy and security concerns.
kurkosdr,
Recaptcha has the concept of “difficulty”. Sometimes google users click right through without any difficulty. Other times google users will be interrupted with captcha (sometimes many captcha prompts to the point of making real humans give up). Google profiles users to determine which users can be let through versus get the harassment experience. I’ve personally verified a few of these factors, some are more surprising than others:
1) The website operator themselves gets to choose a base difficultly setting. Some web operators are temped to set high difficulty without realizing that it can be drastically more difficult for some users, even impossible.
2) If you are logged into a google account, websites using google recaptcha are much less likely to show a captcha.
3) If you are using chrome, you are less likely get a captcha versus a firefox user in an identical browsing scenario. I’m not sure if google looks at user agents, browser fingerprinting, or some secret handshake, but it’s 100% reproducible.
4) If you use a shared IP, you are not only much more likely to get a captcha, but you are m
5) If your profile unfortunately fits all of the above, then you are most likely to get stuck in a non-solvable recaptcha loop where recaptcha difficulty rises beyond the level of annoyance to the level of Denial of Service.
Unfortunately because of my personal desire to be independent from google, I do get stuck at #4 occasionally and this results in some captchas that I, as a human, just can’t get through. If I’m desperate and reliant on using a large public hotspot, switching to chrome is an effective way to reduce the difficulty to get through the captcha. It’s a nice trick to know, but it’s really concerning from an antitrust standpoint.
My guess is that google are going to apply the same type of logic with google play. If you’re device is connected via google play, it will count as a reduction in difficulty and reduce and/or eliminate the captchas. Otherwise it will increase the difficulty for those without google play.
As for the actual mechanism. It’d be possible that they built functionality in chrome to use side channels, but that would probably call negative attention to google. I find it more likely there’s a special “feature” in chrome that google websites including recaptcha can call on to sign a token generated by the local google play instance. This would confirm the presence of google play and could adjust the user’s difficult accordingly. Google might even be able to identify android users that aren’t signed in, but I can’t speak to whether google actually does this.
Studying the “Troubleshoot reCAPTCHA Mobile Verification” page more closely gives me the impression that the QR code does NOT actually open up a browser link like I assumed. It actually requires a recaptcha application to be installed – installable on IOS, and apparently one is bundled with google play services 25.41.30.
So, a recaptcha website would show a QR code say on a desktop, and opening the QR code on the mobile would launch the recaptcha mobile application and use google play services to tell the recaptcha service to unblock the original website on the desktop. Sort of like 2FA but for recaptcha.
Of course this conveniently lets google de-anonymize users in desktop browsers – even third party browsers, VPNs, TOR, they’d all have information shared with google play services identity on the phone. That’s a rather devious scheme if you ask me.
Of course this all assumes the users actually use the QR code, and it makes me wonder whether google would really force them to do so? Can they really get away with blocking users from accessing 3rd party websites if they don’t have a phone blessed by google?
And a bit of a tangent, but suddenly it seems so clear how this very same scheme could be used for “age verification” purposes.
Thanks for reading through this and letting everyone know.
This is worse than I expected, in order to access a website, you have to scan a link with a proprietary app (and you also need to be logged-in to the proprietary app of course). Insane.
Alfman,
We all know they were going to hit this or a similar draconian result for “Web DRM”
I’m not whitewashing this entirely. But if you look at some clips on the social media, bad actors just take motherboards from actual phones, and build massive bot farms that spans walls. They also use malware infected machines… not for mining crypto, but clicking on links.
When Google’s business depends on being able to distinguish “good” vs “bad” clicks, they would of course try to maximize the tools they use.
And unfortunately, this will not get industry backlash… nor anything from the government. (The governments, too want to lock down the web, but their reasons are even more nefarious. Censorship and control vs commercial gain)
Not sure if there are any winning moves at this point, except a massive public pushback campaign.
Internet is worst than the days of pop ups
Pop-ups still exist in the form of overlays that annoy you with privacy consent notices, newsletter nags, and the like.
In fact, they are much more difficult to block than standardized pop-up windows of the past, and most of the time they constitute a “wall” that you have to click through to access the content.
Have you tried Consent-O-Matic?
Yes, you can use such tools, but they have to be updated on a case-by-case basis, this alone proves that you can’t have a universal solution like with window pop-ups. This makes overlay pop-ups more powerful/difficult to block than the window pop-ups of old.
kurkosdr,
It’s a valid point. Annoying website popups (that browsers can block easily) evolved into HTML overlays that often can’t be blocked without a lot more effort. These are very prevalent and I can’t imagine that anyone likes them.
The same was true with Flash. There was a time when a lot of annoying ads and unwanted content were constrained to Flash and that made a lot of anti-features absolutely trivial to block. Ironically apple dropping Flash almost immediately resulted in those anti-features evolving into HTML5, which is practically impossible to block without doing so on a case by case basis. Apple’s public reasoning for blocking flash was to save battery life, but we actually ended up in a scenario where undesirable battery wasting features became no longer blockable. BTW I wasn’t a fan of flash, I’m just highlighting the unintended consequences.
If you try using this scenario on a Google phone with an account that was created without a phone number, for example, when using their Antigravity app, it simply refuses to proceed. It’s not a captcha, it’s a deanonymizer.
Same idea with a much better explanation
https://news.ycombinator.com/item?id=48067505
a_very_dumb_nickname,
Are you implying this is rolled out already? I have been forced to recaptcha recently and I haven’t seen anything like this yet. Of course it could be a phased rollout, is anyone seeing this personally? If so, can you still complete the captcha normally or is completing the QR code mandatory to access websites now? The screen shots show a headset and eye button are still there, do they still work?
I was checking out the Antigravity app, not a website, but the flow is basically the same. You need a phone, and you have to verify your account.
I use GPD MicroPC2 running GNU/Linux, a dumbphone for calls/SMS and a mobile 5G router.
I do almost all my browsing on a Chromebook or desktop computer. When I’m asked to use my phone to scan a qr code to view a web page, I will just close the tab/browser. When statistics show that many users leave the site and views drop considerably they will quickly stop asking to do such things.
I’m the same way (see my other comment farther up). But from what I’ve seen, we are in a small and ever-shrinking minority, while most consumers are increasingly preferring their phones as their primary or even their *only* computing device.
rahim123,
I see that too.. They’ll use a phone exclusively, and it can be painful to watch because they’re often suffering a huge productivity loss because of their preference….Then again I suppose some people don’t notice or care because they’ve never owned a computer, but in social settings my god is it awkward when everyone’s glued to their phones. I don’t know if this is statistically significant or not, but as a computer user, I have very little interest in staring at my phone when I’m out in public, I’d rather wait till I get to a computer.
Yep, especially in less affluent parts of the world where cell phones are the first computing device type that became obtainable for the masses, there are several generations now of people that have never owned or felt the need to own a computer.
But apart from that demographic, I actually have a theory that Windows has contributed to the decline in traditional desktop computing. For so many years, Windows was so objectively bad in terms of stability and security that even experienced users were often at their wits end. Windows has since improved massively in those aspects, but within the circles of users that suffered through that time the reputational damage is already done. There’s also the performance aspect, although I maintain that a *manually installed* *fresh* installation of Windows often feels subjectively faster than the average Linux installation, over time Windows installations tend to become an unwieldy sluggish beast. Then starting in Windows 10 came the forced and sometimes failed automatic updates. Add to that the current and worsening encrapification development cycles that Windows is going through. Users are fed up, but the vast majority of them that don’t care enough to manually install an alternative OS but still need compatibility with the mainstream ecosystem have switched to a mobile device, because it “just works”. No waiting for it to boot up (always on), updates in the case of Android often don’t exist (thanks to the hodgepodge updates ecosystem and planned obsolescence), Apple updates always work, plus the relative security of the vetted app store approach and sandboxing of mobile OSes that prevents most widespread attacks. The overall results in the mobile computing space are dreadful in their own way, but I personally blame Windows for alienating users and forcing them over to the other ecosystem that they think is the only alternative.
spinnekopje,
I hope so. Protests and boycotts of anti-features need to be sizable though, otherwise they can end up existing in the fringes where few notice or care. Microsoft/google/apple/etc often know people are going to protest their anti-features, but they also know that after a few news cycles protests tend to quickly die down and become non-newsworthy. The viability of these schemes depends on average Joes; will they pull out their phones and scan those QR codes ( and install google’s recaptcha app on iphone ) ?
Open source promised things the market could never give us. Instead, we got market products with the source code visible. And the few projects that actually imagine something different? They can’t escape the gravity of credibility — no SLAs, no polish, no enterprise signal — so they stay hobbies. The failure isn’t just imagination. It’s that we built a movement that can’t make non-commercial ideas credible.
Years ago some insisted on differentiate open-source from free(dom)-software. Now we see that in fact they are quiet different concepts
This isn’t just a direct assault on anonymity and open standards, it’s also part of a war against accessibility. Visually impaired and quadriplegic computer users will be blocked completely from accessing any website that uses this new version of reCaptcha. That includes government websites, healthcare provider’s sites, and any other vital resource for getting care and living their lives in a fulfilling and healthy manner. The eugenicist movement in the government is out in the open with the so-called “MAHA” garbage and their burning desire to commit genocide against anyone not “healthy enough” in their eyes.
The US government and tech corps like Google, Microsoft, and Apple want nothing less than to eliminate anyone not “normal”, and they want complete control over anyone who is left after all the undesirables are purged from society. It’s disgusting, it’s inhumane, and it’s evil. We are headed for the dystopian cyberpunk reality that Gibson and Stephenson could never fully envision. Truth really is stranger than fiction.
I freaking hate reCAPTCHA. In some occasions I had to click the mouse more than forty times. I had to put up with the urge to throw my computer out of the window.
There is a way out. I’m running Graphene. and if this comes to pass, I will simply not use tools from the app store. Use firefox instead. Become satisfied with a lower range of apps that are usable. People not giving up on the Google platform is what they want, because people feel too entangled. They are counting on this to drive people to stay put. But people do not have to be entangled, but they must satisfy themselves with a lower compatibility level. That’s what I’m doing. It’s one way out. And I’ll tell you, It’s very quiet over here. Linux Mint doesn’t bother me. My phone doesn’t bother me. Firefox with my pi-hole and ublock origin, doesn’t bother me. Another thing people can consider is what I like to call the Telemetry Black Hole. Firefox has profiles. The profiles do not talk to each other data wise. I use .desktop files and scripts to start sites on different profiles. They can access “all the data” they want. Access to everything, they just can’t correlate the data between sites, because one profile cannot see the data of another. So this breaks that data correlation connection. If you operate say, amazon in a separate profile, they see a user come buy something, and leave. On their side I appear to be giving them all the access they want. Hasn’t failed yet. But they can’t see anyone else’s data. I often clear the data in the “general” profile I have to access sites I occasional go to. If you want to use Chrome, stick it in a minimal docker container. Chrome made it more difficult to isolate data – of course, so shove it’s ass in a container. Then tell it, “in there, you can have all the data you want, you just can’t touch anyone else’s data.” Sometimes walking away and taking the hit is the way to go.
You’re pretty much describing Qubes OS in practice, though in that OS there is even more separation of data than simply using multiple profiles. It can be configured so that every program/application with network access is siloed from the rest in its own container.
Qubes is cool, but … for daily operation? It’s… a lot. the TBH breaks ad correlation which is what all the hubbub is about in the ad hellscape.
I daily drive Qubes for banking, email and youtube. Getting into the 5th year. I love it.
Buying plane tickets? Spin disposable qube.
Google stuff like youtube? Google qube through tor.
My keepass? vault vm without internet.
Bank? its own vm.
its sweet.
on my librem 5, im logged into ars, osnews and the email server i host myself.
thats all.
sometimes I get stuck with captcha, i just dont load the page. and once I was so infuriating by an airline web page being so shitty that I took the bus to the airport.
laxr5rs,
Props to you, browsing using multiple profiles goes beyond what most people do!
For the sake of discussion though, even if you are practicing data isolation, there’s still risk of user agent fingerprinting, which when combined with IP addresses can identify specific devices quite easily. Even if you take steps to protect your IP (like CG NAT/VPN) the fingerprint entropy may be enough to identify a specific device on it’s own without an IP.
Here’s a project that demonstrates this. My fingerprint is “unique”, which is bad for privacy.
https://panopticlick.org/scan/
The more features you change, install, customize, etc on your browser can really act against you when it comes to fingerprinting because the act of changing your browser makes it stand out. For example if you self-host a DNS server, that’s extremely rare and traceable. Ironically non-savvy users who tend to keep everything at defaults (even if those defaults are less private) may actually be harder to identify by being more common. Of course non-savvy users are more likely to fumble and leak their online identity in some other way.
I’m curious what other people see for “fingerprint entropy”, if others wouldn’t mind posting it.