• AmbitiousProcess (they/them)@piefed.social
    link
    fedilink
    English
    arrow-up
    61
    arrow-down
    1
    ·
    10 days ago

    This does seem to work with sandboxed Google Play Services on GrapheneOS btw.

    I scanned the demo QR code on Google’s talk page about it with sandboxed Play Services enabled and it gave me a custom popup asking if I’d like to verify.

      • krashmo@lemmy.world
        link
        fedilink
        arrow-up
        36
        ·
        10 days ago

        Unless you’re doing that from a separate device in a separate location then all you’re doing is giving them the data they need to link those two accounts

        • FauxLiving@lemmy.world
          link
          fedilink
          arrow-up
          23
          ·
          10 days ago

          You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.

          Sandboxed Google Play Services doesn’t have privileged access to location information, so it can’t pull your GPS location or Wifi Positioning information. It would only see a blank profile and doing this would allow for your primary profile to continue to not run Play Services.

          Any malicious code which could be injected into the process would find itself in a sandbox, on a blank profile and isolated from the rest of the system.

          Google would only see that you are authenticating from a profile without anything installed, from an unknown location and coming from whatever VPN endpoint that you’d like. They could possibly infer that the blank profile and your ‘real’ profile are different via browser fingerprinting. You can randomize a lot of fingerprinting datapoints with browser extensions, but avoiding browser fingerprinting is a whole other topic.

          The ‘real’ privacy solution is to avoid anything that uses this version of recaptcha. However, if you have to use these services then you can still reduce the amount of information leaked via Play Services by using a blank profile to scan the QR codes.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            22
            ·
            10 days ago

            You’re right, you’re not going to achieve complete anonymity if you’re interacting with Google services in any way, but you can reduce the amount of information that they receive.

            its not even about complete anonymity. google has zero business in when I’m logging into my utilities company account, or other semi-governmental portals!

            • eldavi@lemmy.ml
              link
              fedilink
              English
              arrow-up
              7
              arrow-down
              6
              ·
              10 days ago

              it literally is their business; they make millions of dollars off of it.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                9 days ago

                then that’s a problem we must solve. Because an adtech company should definitely not have any business in that.

                • eldavi@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  9 days ago

                  it has been solved for approximately 2 billion people on this planet, but those answers are not friendly to profit-seeking institutions like google and the only remaining institutions that can stop it are captured by the likes of google

                  • WhyJiffie@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    9 days ago

                    for the record, I don’t believe logging in with wechat is any better, and recaptcha is present on the utilities websites of my european country leaning towards china.