Live data from Hacker News

Show HN: NextDNS Adds "Bypass Age Verification"

news.ycombinator.com

201–208 of 208 posts

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#201
post #51

Earlier quoted context omitted.

You don't have to sell it like that. The bill that needs to be passed is default presumption that all websites on the internet not explicitly marked as such and who voluntarily accept a higher legal burden and standard of moderation may contain content not suitable for children. And that is up to parents to control their child's internet access to limit their usage to only these sites. Because I don't actually care a…

You're asking for them to set up a system that won't be effective. >And that is up to parents to control their child's internet access to limit their usage to only these sites. This is an entirely unreasonable expectation on parents. I control web access at home, but I can't control it at school, or at their friend's houses. Nor do I have time, nor do I have access, to exert control over all the systems they come in…

Even in the age-verification world you were never safe against friends' houses; my parents bought me porn and took me to a sex shop to pick out toys when I was a teenager. I can't begin to tell you how mortifying that experience was in the moment but in hindsight my parents were just recognizing that teenagers are horny and need an outlet for that. If I were a teenager today I know for sure they would have given me their IDs. And schools have web filters right now today so you don't have to worry about your kids getting access there.

> Like what? Explicit violence?

I find this comment puzzling, you present yourself as someone who desires age restriction of adult content but at the same time only want it for pornography and can't even name other content unsuitable for kids?

Profane language, violence, content about alcohol, content about drugs, content about smoking, blood & gore, "disturbing" content like liveleak, horror, sexually suggestive clothing like titty-streamers, sexually suggestive situations, sex education resources, proana eating disorder content, content about guns and weapons, hate speech, content about suicide and self harm, content depicting and glorifying crime.

When it comes to curating a kid's online experience porn tends toward the bottom of my worry list.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#202
post #137

Earlier quoted context omitted.

I'm really surprised to see this pop up considering how the NextDNS team seems to have disappeared otherwise. Out of date offerings like you mentioned, coupled with 0 customer support when things break (and things break a lot). New features like this are fine only if the base service works. I can guess that this feature also is going to break soon, and I don't have high hopes for it getting fixed. I moved over to Con…

Same here, I left NextDNS because I didn't trust it anymore. I started using it personally in homelab and just found it to be randomly a bit sluggish at times. Saw other similar reports. Tried to get support and failed. I saw it trying to sell itself as business capable DNS, and considered if it would fit in at work. Then I got an e-mail giving 7 days for me to disable and move all my logs out of the EU region. I was…

If you don't mind me asking, what alternative did you move to instead? Control D?

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#203

Earlier quoted context omitted.

Not what I'm saying. At any time before the legit handoff, there can be a decoy which users would be blissfully unaware of, shimmed in. How many times do domains change again during the singup process of whatever service you're using (page to page)? Thats a huge security issue, as it messes with what users expect, and they dont take notice one bit. At the very least its an opportunity to confuse users not to realize…

You are making a vague argument. Do you think it's inherently so unsafe to use your ID in an online context that it is never a net benefit? Yes/No If you think it is unsafe, what alternative do you propose? If you don't have one, or your idea requires some kind of massive simultaneous buy in by all stakeholders and jurisdictions, give up, your opinion is irrelevant.

Yes, forgive me I was trying to cram too many ideas into a short blurb, else I can ramble on forever.

We're just talking past each other, since there is nuance to your original statement I may be not addressing directly.

>Presenting government ID to random entities is literally what government ID's exist for. Paranoia about this is silly.

While this is not wrong, the problem is that with online entities (sites), the act of 'presenting' is the same as 'copying', so in order to present to a 3rd party 'site' you must do something which lets them (if they chose to) copy your ID, and easily allow someone to forge said ID and use it in other situations to 'forge' your identity, a very bad thing. This is critically different than when traditionally 'presenting' an ID when you're boarding a plane or buying alcohol which is an inherently fleeting act(serves its purpose and NOTHING more). Its also why people are uneasy about ID bar-code scanning but that's a huge whole other discussion.

>Do you think it's inherently so unsafe to use your ID in an online context that it is never a net benefit? Yes/No

Its not 'unsafe' on face value, but as with everything else it becomes very complicated very fast. There MUST be safeguards that disallow the occurrence of my first point, otherwise we're in the camp of facilitating ID theft, again 'copying.'

One need not look farther than the credit card ecosystem. Stolen ones are lifted and sold by the thousands. And if you think, 'dedicated services' will be enough to stop increased theft then please let us all know why such a system doesn't solve the PCI problem. It cant and wont. The biggest travesty will be the average user becoming accustomed to scanning their ID (via picture because this is what the discussion is about) and largely getting caught up in slipstream scams like I outlined in previous posts. Id theft will get a boost, and become even more lucrative.

PCI theft is only made 'tolerable' by the fact that cards are trivially replaceable, and this is the important part, current IDs are NOT as trivially replaceable. Plus i can only have ONE, so if it gets pinched, i cant use my other ID to take out a loan. I am ME and cant change, so it makes sense that I may be a little uneasy to give it out to watch twitter cat memes. I don't even need to mention passports, as I’ve done earlier.

>I've had to upload my ID card to send money, open a bank account online, verify my identity for a dating app, book an international flight, and ironically to register for the app to have an electronic version of my id on my phone, and weirdly to pay a traffic ticket (why do they care who pays it?), get a discount on my Amazon Prime subscription, and finally to reset my password for my ID.me login for government websites.

Ok, well herein lies the disconnect, as I've never had to 'present' ID for most of these situations except for government sites in my country, taxes etc, and id like to keep it that way. Its not that I’m against any form if ID, its that it must be fit for purpose.

The whole argument, and this whole discussion is precipiced on the fact that for some reason public discourse is that the status quo, which has worked fine for several decades, must be completely overhauled and we must become accustomed to providing scans of all of our IDs on demand to all services as they are mandated to request them. This is insane. I do not work for an angel-invested ID verification service, therefore there IS NO benefit to myself in advocating for any such requirements, only negatives. It is a complete net loss to require IDs for sites which they are, mind you, completely unnecessary for. Yes, government .gov sites it makes sense, also when taking out loans or other financial information, as they already have huge security hurdles to jump though. Yes I've worked for them so I know. However, requirements for everyone else, INCLUDING PORN sites are unnecessary, the last of which has used credit cards for just such the verification since forever, but like so many other things on earth is inadequate all of a sudden!

Yes, I also do have children, and take the burden of their well-being very seriously. It does not grant me the impetus to persuade the state to try to do my job for me, while in the process creating huge burdensome negative side effects for everyone else.

Traditional IDs are not meant to be 'copied' as they are too costly to replace. This doesn't mean that there couldn't be token-based alternative security authentication services, but that is an entirely different discussion.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#204

Earlier quoted context omitted.

It's a great idea to get rid of, I'm shocked a company is this brave to do this. It's not in the interest of any adult to upload their ID so the government can track their web browsing. I didn't want to expose my kid to porn when they were 5, somehow it wasn't a problem because the avg browser use was guided by me, but also the browser blocked porn. When they were a bit older, a teenager, I also lightly guided their…

The solution to spam is that everyone replies to the spam and engages up to the point that human labor is required, thus making it financially impractictable The solution to this problem is not to provide YOUR ID but to provide AN ID, again and again, once per day. Again - cannot scale if a manual check is done by a human somewhere, flipside if it's fully automated now it's game-able

Interesting idea. If you're of age, then arguably there would be no material deception from using a fake or borrowed ID to prove that you're of age.

I don't believe for a second that this argument would stand up in court, but it would at least be a rational form of protest against having to identify yourself.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#205
post #200
post #197

Earlier quoted context omitted.

In the replies to the reddit thread, I'm seeing a lot of people they tell me they moved to Control D. Some people had complaints about latency of the service and other factors, as it seems Control D doesn't have very extensive worldwide coverage. But, it definitely seems to be the superior option. It's $40 a year more for the full plan, which is unfortunate, but if they offer more options, better customer support and…

Thanks! This was a few years ago for me. It also aligned with my personal pendulum swinging back from cloud to on prem. I switched to local pihole. I didn't really like it though, it felt a bit too toy-like. I then switched to adguard home, and I still use it. I've found it faster, easier and just generally more mature feeling than pihole. Regarding using it away from local area network, I use tailscale (via selfhost…

If you don't mind me asking, what alternative did you move to instead? Control D?

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#206
post #105

Sorry to get on to a related topic, since the NextDNS team may be looking at these comments. Is there any plan at all to revive the iOS app (last updated in 2020) so that the toggle in the app actually works? I don’t like installing a NextDNS profile because it doesn’t offer the flexibility to turn it off or on as needed. The app used to work pre-2020, but doesn’t now. On my iPhone, at any given date and time, it’s j…

I‘m also using the iOS App and I think you need to wait a bit after using the toggle because the DNS requests might be cached by the Browser

Late reply, but the app toggle is always on in my device. But when I visit test.nextdns.io on a browser, it may report a NextDNS endpoint or say “unconfigured”. There’s no way for me to know if it’s working or not at any point in time. It’s broken and the app is abandoned (with no updates since 2020). I don’t want a permanent VPN profile on the device since I’d like to have the flexibility to turn it off if/when needed.

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#207
post #187

Earlier quoted context omitted.

I‘m also using the iOS App and I think you need to wait a bit after using the toggle because the DNS requests might be cached by the Browser

Parent might also be getting bit by Apple's iCloud Private Relay and/or the "Hide IP Address" feature of Safari.

Late reply. I don’t have any iCloud+ subscription and thus don’t have iCloud Private Relay. The NextDNS iOS app is broken and abandoned (no updates since 2020).

Re: Show HN: NextDNS Adds "Bypass Age Verification"

#208
post #188

This sounds like a company using DNS to direct _other_ peoples' web traffic through _their_ proxies. Cloudflare started this way. That's why signing up for Cloudlfare requires using _Cloudflare's_ DNS servers The so-called "DNS trick", which is defintely not a trick, is to redirect traffic though a proxy server. Whoever operates the proxy, e.g. Cloudflare, NextDNS, etc., has control over the HTTPS traffic and _could_…

No, I don't think they are proxying traffic. They are giving the website operators a spoofed EDNS Client Subnet which tricks them into thinking the traffic is coming from a different geolocation.

If this is true, then perhaps unbound users can edit the EDNS subnet module themselves. No NextDNS required
Post reply on HN