Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

151–160 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#151

Earlier quoted context omitted.

Not immediately deleting the selfie is a pretty fundamental and egregious mistake to make. People are particularly sensitive to selfies not being handled correctly after Discord lost thousands of them, despite promising to delete them after age verification occurred (and then not doing so) https://www.bbc.com/news/articles/c8jmzd972leo The damage is limited because the selfie is only retained on device, but it still…

>Discord lost thousands of them, despite promising to delete them after age verification occurred (and then not doing so) This is misleading, yet everyone seems to repeat it. Discord's implementation of ID verification did not retain IDs. Reporting on this was so poor, but what appears to have happened was that people that failed age estimation / ID checks had to raise a support ticket and get manually reviewed. That…

This is a distinction without a difference. Users were assured their selfies would not be retained and they were. Discord then proceeded to lose those selfies to bad actors, after promising not to retain them. The incident has caused enormous distrust of all age verification systems, which were already starting in the mind of the community from a base level of skepticism. It's already highly invasive to take a photo of yourself, but then the user must trust that the organization on the other end will handle it appropriately. To have that trust so conspicuously broken poisons the well for all other age verification systems and websites that are legally compelled to use it, or face penalties from aggressive organizations like OFCOM.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#152
post #130

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

The assembly seats in Brussels, so the decision comes from Brussels (geographically). It doesn't imply that people from Brussels are the ones to decide, not everyone has the same idea anyways. Though, as citizens of a EU member state, they have some responsibility, at least indirectly.

Brussels is the seat of five governments: the city itself, the Brussels-Capital autonomous region, the Flemish Parliament and Government (luckily the Wallon Government seat is in Namur), the Belgian Federal Parliament, and the European Commission and Parliament.

The "Brussels" metonym is probably the most ambiguous reference to a government body on the planet.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#153

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

It’s very common throughout English. The Russian government is refered to as Moscow, US as Washington. It’s the same and doesn’t refer to residents. It’s known as synecdoche. In other words, sorry but it’s here to stay.

The problem here, and the source of OOPs annoyance I think, is that the governments of the constituting member states have the habit to present unpopular regulations as 'from Brussels' while taking credit for the popular things as from 'Den Haag','Berlin' or 'Paris' or whatever the local capital is. This habit is the main driver of anti-EU sentiments across the whole of europe. Which is a pity, mainly because it takes the attention away from highly needed reforms in the EU structures because people who could drive the reforms now just want out.

So while linguistically it's the same system as using 'Washington' or 'Moscow', Brussels is specifically in the bad spot where it gets blamed for impopular stuff but never praised for popular things.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#155

This all feels a bit like letting children into a nightclub and then needing to see ID every time you buy a drink.

Right? It seems to me that the filter should be at the device level by the parents.

What if they use someone else's device though? Or circumvent the filter? Come on, this is Hacker News, "we" circumvent guardrails because we can and because we know no security is perfect, often from a young age.

I love how a lot of the "this is the parents' responsibility" opinion-havers don't seem to remember what it was like to be a kid themselves and / or don't have kids of their own.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#156

Earlier quoted context omitted.

... isn't this how most bars/pubs work?

The metaphor still works, minors in pubs are, presumably, under the supervision of their parents, otherwise they have not business being there in the first place.

That's a big "presumably", lots of teenagers go out you know.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#157
post #109

It would be possible to implement age verification in a way that would somewhat work and that would be to use the correct crypto on an government issued ID card. Crypto where the OS (or a website) can ask the card: "Is the holder of that card over X years old y/n?" and the card would just answer with a binary yes no question without exposing any other data while still checking the government signature. Obviously that…

in the Netherlands we have a better system called iDIN; it works like doing an online payment (iDeal / WERO):

* Website asks for age verification * User is redirected to their bank * Bank asks the user to log in - username/password, 2fa, bank app (whose login is behind the device's security and a secondary verification like PIN code or biometrics) * Bank tells the requester that the user is 18+, no more

This leverages a trusted party (your bank, which is subject to heavy IT security regulation and audits) and you need to show ID to open an account anyway), secrets only you know (and your kids can't easily take), phone security systems, etc. Does not require uploading ID to a 3rd party, does not require changing how IDs work, etc.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#158
post #8
post #4

"Let’s say I downloaded the app, proved that I am over 18, then my nephew can take my phone, unlock my app and use it to prove he is over 18." - and how is that something that could, or should, be addressed by the app? Are we even serious??

Because people share phones with their kids. It's not rare or even mildly unusual. The problem isn't that the app needs to solve this. The problem is the app is useless, along with this whole bizarre "need for age verification" plot that poofed out of existence simultaneously around the whole globe mysteriously a few months ago.

That's why a lot of apps have a secondary login (PIN code, biometrics).

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#159
post #15

On top of the pretty bad article, HN finds the “can’t win” scenario again. There’s no age verification scheme that will survive “collusion”, that’s when the adult allows the minor to use validated credentials, devices, etc. And whatever more intrusive age verification schemes we come up with will also fail this but add the intrusiveness to ruffle even more HN feathers. We can have the constant face, fingerprint and D…

The first premise you are avoiding is that a child can misuse a phone. The second premise you are avoiding is that the government can define , for every child, what constitutes misuse. You are advocating thought crime. You do not have my support. My government cannot adequately manage responsibility for my cupboards. It therefore shall not have authority over them.

Your government does have various authorities over what you put in your cupboards though. like, you can't just put a gun in there (actually I don't know where you live but that's true for most countries). You can't just get in a car.

Anyway, ultimately it's best effort. No security is flawless, but if it stops 99% or more of cases it's better than 0%.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#160

Earlier quoted context omitted.

> It is my understanding that this is not possible. I would be happy to be shown to be wrong, but to me it seems like you can either prevent people from lending out their credentials, or you can preserve the anonymity of the user, but not both. This is not designed to prevent adults from coöperating with minors; that makes no sense as a design goal because any technical measure can always be bypassed with “download t…

But laws against selling/giving alcohol to minors are moderately successful at curbing teen alcohol use because they carry with them a risk of punishment that grows with the scale of the operation. If all it took was one adult who thought "kids should be allowed to drink if they want" to provide all the kids in the country with free booze and that adult had no meaningful fear of repercussions, the laws would be nothi…

It's always fascinating when people put "tor hidden service" in a sentence that describes something that will reach millions.

I also don't think you'll find many ISPs terribly keen to fight for the neutral treatment of TOR connections when the reason for this fight is explicitly to serve porn to minors.

Post reply on HN