HeadlinesBriefing favicon HeadlinesBriefing.com

reCAPTCHA Mobile Verification Brings Hardware Attestation to Desktops

Hacker News •
×

Google's reCAPTCHA Mobile Verification is extending hardware attestation to desktop systems. The service uses a QR code scan from a certified smartphone to verify users on Windows, Linux, and other platforms. Apple's Privacy Pass and Google's Play Integrity API work on similar principles, requiring devices approved by either company before granting access.

Banks and government services have been the primary adopters, but adoption is spreading. The EU is mandating these requirements for digital payments, identity verification, and age checks. Google's Play Integrity API blocks GrapheneOS despite its superior security, while permitting devices with no security patches for 10 years — suggesting the purpose is lock-in rather than genuine security.

Control over reCAPTCHA puts Google in a position to require either iOS or a Google-certified Android device for a vast share of the web. GrapheneOS can technically pass hardware attestation, but Google bans it because it doesn't bundle Google Mobile Services. This structure locks out competition under the guise of security.