AUTO-UPDATED

Google's new remote attestation scheme is every bit as terrible as its old remote attestation scheme

Google is testing a new "reCAPTCHA Mobile Verification" feature that uses device hardware to identify and potentially block users running independent, privacy-focused versions of the Android operating system.

Key Points

  • The experimental tool utilizes a device's Trusted Platform Module (TPM) or secure enclave to verify software configurations.
  • It aims to restrict access for users of "de-Googled" Android alternatives like CalyxOS, PureOS, and GrapheneOS.
  • This initiative follows previous controversial proposals like Web Environment Integrity (WEI), which sought to force devices to disclose system details to servers.
  • Critics argue these measures undermine user agency by preventing the use of ad-blockers, privacy tools, and accessibility modifications.
  • Google faces ongoing scrutiny for its market dominance, including recent federal antitrust rulings regarding its search and advertising practices.

Why it Matters

These technical restrictions threaten the open nature of the web by allowing companies to dictate how users interact with digital services. By enforcing "walled garden" environments, Google risks centralizing control over user privacy and limiting the ability of individuals to modify their own devices.
EFF Published by Cory Doctorow
Read original