Hacker Newsnew | past | comments | ask | show | jobs | submit | deltoidmaximus's commentslogin

Can you actually make a Google account without a phone number these days?

I always ran it with the 2000 style theme. That said XP offered me nothing over 2000 so 2000 is what I ran on my main machine since it used less ram but did all the same things, often a bit faster.

For awhile I ran XP 64-bit though, that did do one thing 2000 couldn't do.


I guess I'm more cynical at this point. This isn't the 1970s when a congressman freaked out that his video rental history might leak and passed a law making them private for everyone as cover. They've evolved beyond that. They'll pass a law banning it for individuals but leaving a loophole for themselves. Like how Chat Control always contains a provision so that officials messages aren't a part of the dragnet.

> I guess it's a good thing I don't really give a crap about Instagram in the first place, isn't it.

If you were willing to upload your driver's license and passport for a mere chance at getting back an account you don't give a crap about I'd hate to see what you'd do for one you do care about! Facebook demanded my driver's license at one point out of the blue. I simply abandoned the account, I was already pretty over them at that point anyway. About a year later it let me log in just fine and had forgotten all about how badly it had needed a scan of my license for security. In fact I didn't even remember the password, it just auto logged in from an email link.

You kind of confirm what I suspected though, that they'll just keep asking for more stuff leaving you more exposed and they're under no obligation to actually give you the account back no matter what you do.

I don't use discord but IIRC I read that if your account was banned they were asking for a mobile number to get it back. Instead of getting it back if you complied they just added the mobile number to their ban list so you couldn't make a new account with it.


I largely don't use Windows anymore, but there is an option buried under Advanced System Settings/Properties under the hardware tab called Device Installation Settings. There you can turn this off (marked 'not recommended').

I know about this because I have a Windows 10 VM that was automatically installing an old broken Radeon driver through it that would just leave me with a black screen on boot. I also learned that if Microsoft got the scent of the driver and started downloading it turning this option off didn't stop that particular driver from continuing to download and hosing the install. Since I lacked a snapshot before this I had to reinstall the the entire OS in the VM with the GPU not passed through and then turn the option off first.


LG recently was in the news for loading Microsoft's utility/driver update mechanism with crapware that auto installs (by default) when you hitch one of their monitors to a Windows PC. I fear they just haven't gotten around to fully abusing monitor users yet.

That's just your computer having the same who-is-the-owner issue as a smart TV.

I'd love to hear more about that. I didn't think Workstation could do anything besides USB device passthrough!

I’ll be honest it’s been over 10 years at this point. But we had to virtualize a dying Gateway 2000 that had Windows XP on it. As part of that we needed ISA to keep working. I found some USB ISA adapters and ordered them. It took a lot of messing around with Workstation, the host Windows 7 and drivers on the VM. I can’t remember all the details at this point :(

Captchas are often used as tarpits. They've already decided you're a bot based on other factors so you aren't getting in until you change those factors. I've seen this happen where I'm stuck in the loop and then change the VPN endpoint and get right in after one try.

I'm sure there exist examples where people maliciously give tasks (captchas) out that have no chance of getting the person anywhere, but it's definitely not common

Consider yourself lucky. I routinely run into tarpit Google reCAPTCHAs and I don't even use a VPN. I think it's because I run Linux and the site admins treat anything besides Windows, Mac, iOS, or Android Chrome as suspicious enough to blacklist. It has gotten to a point that I literally never even _try_ to do image-based CAPTCHAs anymore. If I can't access the site, oh well.

I also get infinite captchas but it's imo not a tarpit if it's not intentional but a bug

Edit: looked up the term, DDG shows a Wikipedia card saying "A tarpit is a service on a computer system that purposely delays incoming connections." (purposeful)

It may seem purposeful on Google's part but I bet that if we could get through to the developers for answers, it's probably not designed that way but we're running into a case where the system isn't designed to handle it

Which could be said to be intentional (excluding people with our FOSS setup), I guess


To where, the site requesting the verification? Now it is no longer zero knowledge.

No, to the ID to prevent abuse if the card get stolen.

Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key.

The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.

Your system effectively collects exactly the data ZKP is intended to protect.

Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.


Nope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP.

No third part would know how often you use your ID.

Why do people make up problems that are already solved?

OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.


My example is still just as good if the ID holder is complicit.

But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.


And create new requirements normalizing id verification for increasingly mundane things assuring citizens are exposed to ever more breaches.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: