{"id":17226,"date":"2026-05-14T11:13:22","date_gmt":"2026-05-14T18:13:22","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=17226"},"modified":"2026-05-14T11:14:49","modified_gmt":"2026-05-14T18:14:49","slug":"the-web-is-splitting-into-approved-and-unapproved-humans","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/05\/14\/the-web-is-splitting-into-approved-and-unapproved-humans\/","title":{"rendered":"The Web Is Splitting Into Approved and Unapproved Humans"},"content":{"rendered":"\n<p>What ever happened to Google&#8217;s &#8220;Don&#8217;t be Evil&#8221;? Oh, they deleted it which is a tell they are going to be evil. I think this is part of the larger scheme coordinated with age verification laws and lawsuits, all to make the internet a pain to use so you&#8217;ll accept digital ID, eventually requiring an AI agent on your machines to keep tabs on you. And when you&#8217;re identified, Tor and VPNs won&#8217;t really matter anymore, because nobody will have privacy or anonymity. And <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/04\/13\/eyeball-id-verification-is-here\/\" target=\"_blank\" rel=\"noreferrer noopener\">Mexico will soon make you biometrically identify yourself for a phone number<\/a>, with the <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/05\/06\/the-fcc-wants-your-id-before-you-get-a-phone-number\/\" target=\"_blank\" rel=\"noreferrer noopener\">FCC recently calling for government ID uploading for a phone number<\/a>. They&#8217;re really ramping up for the Mark of the Beast system, and it is a worldwide coordinated effort that shows the world is run by the OCGFC, Owners and Controllers of Global Financialized Capital, and you know who they report to, the soon to be revealed Antichrist.<\/p>\n\n\n\n<p><a href=\"https:\/\/reclaimthenet.org\/google-fraud-defense-web-attestation\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/reclaimthenet.org\/google-fraud-defense-web-attestation<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_87f77ddc-63ed-4b76-95d4-677650e74dc6\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-1024x576.png\" alt=\"\" class=\"wp-image-17227\" srcset=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-1024x576.png 1024w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-300x169.png 300w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-768x432.png 768w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-1536x864.png 1536w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/05\/image-12-2048x1152.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Google asked permission to gate the open web in 2023, got rejected, and just shipped the same thing as a product update nobody voted on.<\/h5>\n\n\n\n<p>By Rick Findlay<\/p>\n\n\n\n<p>In 2023, Google proposed something called Web Environment Integrity. The idea was that websites could check whether your browser was running on Google-certified hardware before letting you in. Mozilla opposed it.<\/p>\n\n\n\n<p>Brave said it would never ship the feature. Vivaldi warned that \u201cany browser choosing not to implement this would not be trusted, and any website using this API could therefore reject users from those browsers.\u201d<\/p>\n\n\n\n<p>Google withdrew the proposal within months. The public won.<\/p>\n\n\n\n<p>Three years later, though, at Cloud Next \u201926, Google announced <a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-fraud-defense-the-next-evolution-of-recaptcha\">Fraud Defense<\/a>, billed as the next evolution of reCAPTCHA. It uses the same Play Integrity API. It requires the same Google-certified hardware and it performs the same device attestation. The difference is that Google didn\u2019t ask anybody this time. There was no standards process or public review. The requirements page just went live and Fraud Defense shipped through reCAPTCHA\u2019s existing install base of more than 14 million domains.<\/p>\n\n\n\n<p>The standards process that killed WEI existed for a specific reason, which was to prevent a single company from deciding who gets to use the open web. Google found a workaround. It launched the same mechanism as a commercial product.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How reCAPTCHA Already Punishes You for Not Being a Google Customer<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/reclaimthenet.org\/wp-content\/uploads\/2026\/05\/7qXptYpTnznk.jpg\" alt=\"Checkout page overlay showing a QR code reCAPTCHA titled &quot;Scan to Verify You're Human&quot; over an order summary.\" class=\"wp-image-239730\"\/><\/figure>\n\n\n\n<p>The scoring has been rigged for years. reCAPTCHA v3 assigns every visitor a risk score between 0.0 and 1.0. Technology consultants who tested the system found that browsers logged into a Google account consistently received low-risk scores, while the same sites visited through Tor or a VPN got flagged as high risk.<\/p>\n\n\n\n<p>Being logged into Google, handing your browsing data to the company\u2019s tracking apparatus, is treated as evidence that you\u2019re human. Protecting your privacy is treated as evidence that you might be a bot.<\/p>\n\n\n\n<p>Anyone who\u2019s used a VPN has experienced this firsthand. Stay logged into your Google account and reCAPTCHA waves you through with a single click, or no challenge at all. Log out, switch to Firefox, enable a tracker blocker, and the puzzles start. They loop. They get harder. Sometimes they never resolve.<\/p>\n\n\n\n<p>VPN users face something even worse because VPN server IP addresses are shared by thousands of people. The behavior of a few users poisons the reputation of the entire address. Low-reputation VPN IPs trigger CAPTCHA rates between 80 and 100 percent, with harder puzzles on top of that.<\/p>\n\n\n\n<p>Privacy extensions like uBlock Origin and Privacy Badger can interfere with reCAPTCHA scripts entirely. The result is infinite challenge loops where verification becomes impossible, no matter how many crosswalks you correctly identify.<\/p>\n\n\n\n<p>reCAPTCHA difficulty scales inversely with how much Google knows about you. That\u2019s the system working as designed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The People This Actually Hurts<\/h2>\n\n\n\n<p>Researchers who scanned the entire IPv4 address space <a href=\"https:\/\/www.cio.de\/article\/3686070\/tor-users-increasingly-treated-like-second-class-web-citizens-4.html\">found<\/a> that 1.3 million websites refuse connections from known Tor exit nodes. Around 3.67 percent of the top 1,000 websites block Tor users at the application level. The researchers concluded that Tor users are \u201ceffectively being relegated to the role of second-class citizens on the Internet.\u201d<\/p>\n\n\n\n<p>Tor\u2019s own documentation acknowledges the problem. Websites interpret shared exit relay traffic as suspicious, hitting users with CAPTCHAs, temporary blocks, or warnings about infected traffic. None of which reflects anything the individual user has actually done.<\/p>\n\n\n\n<p>The people who rely on Tor most are journalists working under hostile governments, dissidents, and domestic abuse survivors trying to communicate without being tracked. Anonymous communication is a lifeline for people whose internet access is controlled by states that would harm them for using it freely. CAPTCHA systems treat them identically to automated botnets.<\/p>\n\n\n\n<p>Fraud Defense makes this worse. Google\u2019s requirements page specifies what hardware qualifies for the new QR code challenge. Android phones need Google Play Services version 25.41.30 or greater.<\/p>\n\n\n\n<p>That requirement excludes every de-Googled Android device. GrapheneOS, the security-hardened fork used by privacy enthusiasts, cannot satisfy Play Integrity checks at the level Fraud Defense demands. LineageOS, CalyxOS, and any custom ROM that strips out Google\u2019s proprietary software layer fail for the same reason.<\/p>\n\n\n\n<p>Firefox for Android does not appear in Google\u2019s browser support list. Mozilla\u2019s position on device attestation was stated clearly in 2023 and has not changed. Users of the most privacy-respecting major mobile browser are excluded from verified access by default.<\/p>\n\n\n\n<p>Meanwhile, iOS users pass without installing any Google software. If the requirement were actually about security, Apple\u2019s approach proves device attestation works without Google\u2019s proprietary stack. The fact that Android users specifically need Google Play Services tells you where the real requirement lies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Hierarchy<\/h2>\n\n\n\n<p>The system Google has built creates an access hierarchy for the web and it\u2019s worth spelling out who sits where.<\/p>\n\n\n\n<p>At the top are users logged into Google accounts, browsing in Chrome on a residential IP. They almost never see CAPTCHAs. Below them sit ordinary users who get occasional puzzles, minor friction, and standard image grids. Below them are VPN users, facing constant challenges because their shared IP addresses are permanently flagged.<\/p>\n\n\n\n<p>Users report multiple CAPTCHAs per session as a baseline. At the bottom sit people running Tor, de-Googled phones, Firefox with anti-fingerprinting settings, or browsers configured to reject tracking cookies.<\/p>\n\n\n\n<p>For these users, the experience ranges from infinite CAPTCHA loops to outright blocks. With Fraud Defense deployed, it becomes total exclusion from sites that use it.<\/p>\n\n\n\n<p>Privacy is penalized and surrendering your data is rewarded with frictionless access. The old system punished privacy-conscious users with harder puzzles. Fraud Defense can lock them out entirely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Surveillance Part Google Doesn\u2019t Talk About<\/h2>\n\n\n\n<p>The Fraud Defense challenges that resolve successfully transmit a signal to Google. This certified device accessed this site at this time. A device with a stable hardware identity generates a persistent identifier that survives session boundaries, browser switches, and private browsing modes. The company deciding which hardware is legitimate also accumulates a running log of where that hardware goes on the open web.<\/p>\n\n\n\n<p>This sits on top of data harvesting reCAPTCHA was already doing. The French data protection authority, CNIL, found that reCAPTCHA collects IP addresses, cookies Google deposited on the device over the previous six months and a list of browser plugins, and that this data serves purposes beyond security.<\/p>\n\n\n\n<p>Google\u2019s own terms of use tell companies deploying reCAPTCHA that the system collects hardware and software information and transmits it to Google for analysis, and that it is their responsibility to inform users and obtain consent.<\/p>\n\n\n\n<p>reCAPTCHA also sets persistent cookies that enable cross-site tracking. Under the ePrivacy Directive and GDPR, these require explicit prior consent. If a user declines cookies, the reCAPTCHA script is not supposed to load, which breaks form functionality on any site using it. Users are forced to trade privacy for access, a consent mechanism that fails the GDPR\u2019s requirement that consent be freely given.<\/p>\n\n\n\n<p>The QR code mechanism adds hardware-level device identification on top of all of this. The system that verifies you are human also verifies your device, your location, and your identity to an advertising company.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Bot Problem Fraud Defense Doesn\u2019t Solve<\/h2>\n\n\n\n<p>Bot operators can point a camera at a screen to scan the QR code. That is trivial automation with off-the-shelf hardware. A Play Integrity-compliant Android phone costs about $30. For a professional bot farm buying devices in bulk, that is negligible overhead.<\/p>\n\n\n\n<p>The people Fraud Defense actually excludes are privacy-conscious users, de-Googled phone owners, Tor users, and people in countries with repressive governments. These are the populations least likely to be running botnets. The actual bot operators absorb the cost and keep going.<\/p>\n\n\n\n<p>There\u2019s a separate problem that has nothing to do with bots. Security professionals have raised concerns about users being unable to distinguish a legitimate Google CAPTCHA QR code from a phishing QR code. The system trains people to scan codes reflexively to access websites. QR-code phishing attacks have already more than doubled in early 2026. Google built a system that makes phishing easier while failing to stop the bots it was supposedly designed for.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Europe Already Knows<\/h2>\n\n\n\n<p>The CNIL <a href=\"https:\/\/www.hunton.com\/privacy-and-cybersecurity-law-blog\/cnil-issues-e125000-fine-against-e-scooter-rental-company\">ruled<\/a> that reCAPTCHA enables analysis by Google beyond securing authentication and fined companies for deploying it without proper consent. The Bavarian State Office for Data Protection Supervision found that Google\u2019s lack of transparency about what data reCAPTCHA actually collects makes privacy compliance effectively impossible, because website operators cannot inform users about processing they don\u2019t fully understand themselves.<\/p>\n\n\n\n<p>Data transfers to US servers conflict with the <a href=\"https:\/\/www.gdprhub.eu\/index.php?title=BVwG_-_W298_2274626-1\/8E\">Schrems II ruling<\/a>. Multiple European authorities, in France, Austria, and Bavaria, have taken enforcement action against reCAPTCHA deployments.<\/p>\n\n\n\n<p>Google\u2019s response, announced in April 2026, was to move to data processor status, which nominally gives organizations control over user data. But the data still flows through Google\u2019s infrastructure. Website operators now bear GDPR compliance responsibility for a system whose data practices they cannot fully audit. Google moved the legal risk to its customers and changed nothing about the pipeline.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Alternatives Nobody Uses<\/h2>\n\n\n\n<p>Cloudflare Turnstile runs invisible verification with no device attestation and no Google dependency. It uses Private Access Tokens, collaborating with device manufacturers to validate devices without collecting or storing the data itself. It is free.<\/p>\n\n\n\n<p>Proof-of-work systems like Friendly Captcha and ALTCHA issue cryptographic challenges where computational cost scales with volume. One human pays a negligible cost. Bot farms running concurrent sessions face exponentially increasing compute expenses. No hardware identifier is transmitted and no certification layer determines who gets access.<\/p>\n\n\n\n<p>These systems prove you are human without requiring you to identify yourself or your device to an advertising company. The difference from Fraud Defense is categorical.<\/p>\n\n\n\n<p>Adoption remains slow for the obvious reason. reCAPTCHA commands roughly 85 percent of the CAPTCHA market and is embedded on more than five million websites. Web developers keep deploying reCAPTCHA because it is the default, because it integrates with Google\u2019s wider ecosystem of Ads, Analytics, and Cloud, and because switching feels risky even when the alternatives are technically and legally superior.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Pattern<\/h2>\n\n\n\n<p>AMP controlled content distribution, privacy Sandbox controls ad targeting, fraud defense controls who is allowed on the web at all. All of these products extend Google\u2019s role as gatekeeper over progressively larger portions of the internet\u2019s basic functionality.<\/p>\n\n\n\n<p>Vivaldi\u2019s 2023 warning has aged well. If attestation became standard, \u201cany browser choosing not to implement this would not be trusted, and any website using this API could therefore reject users from those browsers.\u201d<\/p>\n\n\n\n<p>Google could mandate that sites using Google Ads deploy Fraud Defense, and any non-compliant browser or operating system would be finished.<\/p>\n\n\n\n<p>The web is splitting into attested devices and unattested devices. Privacy-conscious users are being pushed into a second tier where services disappear because they refused to run proprietary software from an advertising company.<\/p>\n\n\n\n<p>The question was never whether the web needs bot protection. Of course it does. The question is whether bot protection requires handing one company a persistent hardware-level identifier for every user on the internet, when alternatives that don\u2019t require that already exist.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What ever happened to Google&#8217;s &#8220;Don&#8217;t be Evil&#8221;? Oh, they deleted it which is a tell they are going to be evil. I think this is part of the larger scheme coordinated with age verification laws and lawsuits, all to make the internet a pain to use so you&#8217;ll accept digital ID, eventually requiring an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-17226","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=17226"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17226\/revisions"}],"predecessor-version":[{"id":17230,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17226\/revisions\/17230"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=17226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=17226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=17226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}