cross-posted from: https://infosec.pub/post/9936059
I would like to collect the scenarios in which people are forced to enter Google’s #walledGarden (that is, to establish and/or maintain an account).
If someone needs a Google service to access something essential like healthcare or education, that’s what I want to hear about. To inspire a list of things that are “essential” I had a look at human rights law to derive this list:
- right to life
- healthcare
- freedom of expression
- freedom of assembly and of association
- right to education
- right to engage in work and access to placement services
- fair and just working conditions
- social security and social assistance
- consumer protection
- right to vote
- right to petition
- right of access to (government) documents
- right to a nationality (passport acquisition)
- right of equal access to public service in his country
Below is what I have encountered personally, which serves as an example of the kind of experiences I want to hear about:
- Google’s Playstore is a gate-keeper to most Android apps in the world and this includes relatively essential apps, such as:
- emergency apps (e.g. that dial 112 in Europe or 911 in the US)
- banking apps
- apps for public services (e.g. public parking)
- others?
- (education) Google docs is used by students in public schools, by force to some extent. Thus gdocs sometimes cannot be escaped in pursuit of education. When groups of students collaborate, sometimes the study groups impose use of gdocs. Some secondary school teachers impose the use of Google accounts for classroom projects.
- (education) A public university’s wi-fi network involved a captive portal and the only way to gain access was to supply credentials for a Google or Facebook account.
I’ve noticed that when creating an account for a public service I often have the option to supply credentials for Google or Facebook to bypass the verification process. In all cases of this kind of registration shortcut being used for public service, there was an alternative Google-free way to open the account. But in the private sector, I’ve seen this style of registration that absolutely required a proxy login via some shitty walled garden (like the university wi-fi). So I wonder if there are any situations where a government (anywhere in the world) requires a Google account in order to get service.
What’s TAN?
(edit)
Regarding the train svc, the carsharing, Netflix, etc, I generally draw a line and say all the private sector stuff can be disregarded apart from life essentials like groceries. So in your list, the train service is a good point because that’s a public service which invokes human rights (equal access to public service). Since you mention Germany, I happen to recall some Germans saying that the train app can access tickets and fares that are otherwise unreachable, perhaps in part because some stations have no kiosk.
Re tickets: Many people in Germany use a kind of flatrate of 50€ per month for regional and local public transit, which either comes with a plastic card or an app. Politicians discouraged the card as ‘less modern’ and many people don’t even know about the card. Basically all train stations for interregional trains (InterCity Express (ICE), InterCity (IC) and EuroCity (EC)) have a way to aquire printed tickets.
That sounds like a good option for regular users and locals. Can that card be bought anonymous non-residents using cash? It would seem to eliminate a lot cases of non-phone users getting screwed but I guess there would still be tourist cases where the 50€ is unjustified. Like if someone is just passing through and needs to change airports (though I guess those are also not the cases where someone would be forced to use a phone app).
Practically only Germans can subscribe, as an address and a bank account is required for the ticket.
Transaction number. It’s a second factor for authentication of basically everything you want to do while banking online.
Most people use a phone app for it (which doesn’t reliably work on degoogled and rooted phones), but you also have the choice of buying a dedicated TAN generator device, so people without smartphones can use online banking.