Live data from Hacker News

What we call "age verification" is actually mass surveillance

pluralistic.net

381–390 of 520 posts

Re: What we call "age verification" is actually mass surveillance

#381
post #334

Earlier quoted context omitted.

> If you don't have an answer to the question of why someone should have to pay again to use the Internet Of course I have an answer. To do something about the unlimited firehose of porn, violence, divisive, and addictive content that has been pointed at children for the past generation or so. There's literally nothing confusing about the "why" in this discussion. The fact that bad people use the "what about the chil…

>To do something about the unlimited firehose of porn, violence, divisive, and addictive content that has been pointed at children for the past generation or so. See, you've answered a different question. The question you answered is, "why should children be protected from the Internet?" I'll give you for free that children should be protected from the Internet, for the reasons you've said, and now you get to convinc…

> I, who don't have or plan to have children, should spend my money to protect other people's children from the Internet.

For the same reason your taxes pay for schools even when you don't have kids.

Because we live in a society.

If you struggle to understand why that matters without reference to more direct personal stakes for yourself, just know that without a society, the children will grow up to rape you, kill you, and possibly consume you for your protein content.

Re: What we call "age verification" is actually mass surveillance

#382

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

> The website only sees the ‘over_18’ attribute

I don't believe this.

Re: What we call "age verification" is actually mass surveillance

#383
post #149

The main problem is providing infrastructure for a government that can over use it in future if move to ultra right/left/authoritarian spectrum Just for example Russia build infrastructure for blocks website for child safety, but it started to used much further

> The main problem is providing infrastructure for a government that can over use it in future if move to ultra right/left/authoritarian spectrum

If that was considered the real problem, we would be fighting against surveillance capitalism. Instead we cheer for LLM companies who made it an order of magnitude worse.

Let's be honest, the only time we care about being tracked is to access porn, for some reason. And if we're being honest, we are already tracked when doing it.

Re: What we call "age verification" is actually mass surveillance

#384

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

> Could you be more specific as to what you're imagining? sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic. - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is no…

> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time

Exactly, prepaid phone cards with point of sales activation (to eliminate large scale theft incentive) is nothing new. Once activated, the validity of the token can be like 6 months or one year, and at-most-once-per-domain schema can be managed by the issuing authority if they want.

Instead of a 100 phone minutes, 300 phone minutes card you just buy "I'm over 16", "I'm over 18" cards. It's simple UX.

Re: What we call "age verification" is actually mass surveillance

#385
Not that I am in favour of age verification, but I find it interesting how many people complain about age verification for being "mass surveillance", but just don't give a shit about AI and TooBigTech and surveillance capitalism.

Let's be honest: "they" already know our age.

Re: What we call "age verification" is actually mass surveillance

#386
post #232

Earlier quoted context omitted.

> there are several reasonable proposals that would be 90%+ successful without stepping on anyone's toes. I have a feeling my definition of having my toes stepped on differs dramatically from yours. > i am convinced that enough people in power know it, too, but see this as their chance to get the full-dystopia version rolled out. Well there's plenty of idiots in power and I'm sure they have no idea. But there absolut…

> I have a feeling my definition of having my toes stepped on differs dramatically from yours. based on what?

My assumption (made admittedly with no evidence whatsoever) that you believe it's possible for someone to verify their age without giving up any anonymity or privacy, even temporarily.

Re: What we call "age verification" is actually mass surveillance

#387

Earlier quoted context omitted.

> The website only sees the ‘over_18’ attribute, which is backed by the government signature Not true. The device's public key is also sent, which functions as a stable device identifier. We've spent years trying to get away from stable tracking IDs and fingerprinting. Returning to a system where devices are sending a stable ID to a website to prove ownership is a step backward. There are proposed mitigations like is…

> Not true. The device's public key is also sent, which functions as a stable device identifier. This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. The wallet will automatically request new credentials in batches…

> This is covered by allowing for single-use credentials.

They said There are proposed mitigations like issuing multiple sets of credentials or rotating them, but we're not going to get an infinite number of keypairs for every website or session in the secure enclave in practice.

> Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs.

The comments you replied to omitted mass surveillance. But the article and 1st comment included it. The government would know what wallet requested each single use identifier.

Re: What we call "age verification" is actually mass surveillance

#388

Earlier quoted context omitted.

> To effectively keep adult content away from kids, it merely requires secure boot and closed app stores, which are already widespread. And they are only required on the devices actually given to kids, rather than every single computing device. ...I guess I don't really see the difference. Closed app stores are widespread on some platforms but certainly not others, and I for one would really like them to not spread a…

For starters here, the difference is that only devices that parents give to kids need to have secure boot and controlled software sources. The point is that every other device remains completely unaffected. But in general there is a huge difference between the freedom-destroying properties of secure boot with closed app stores, and the next step of remote attestation. Remote attestation lets the server insist that yo…

No, thank you. As a parent, I want to give a device to my child that they can hack, just like I had.

Why are we treating kids like adversarial threats? If my kid gets around parental controls, I’ll revoke their phone privileges. No need for invasive security.

Re: What we call "age verification" is actually mass surveillance

#389

Earlier quoted context omitted.

In fairness (i.e. looking at the data with an open mind), social media does seem to be the cause of (or at least strongly correlated with) a bunch of ills.

That's true but has anyone studied the good things that have happened from younger people being able to find community or other positive aspects? Either way the solution again is not age gating, it's real meaningful data privacy laws that if enacted would have a huge effect on many companies today.

How do data privacy laws address the significant number of voters who are being told and believe that social media use is causing issues for children and want something done about it?

This is exactly what I mean: you've rocked up and started talking about something else entirely.

Re: What we call "age verification" is actually mass surveillance

#390
post #368

Earlier quoted context omitted.

> Could you be more specific as to what you're imagining? sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic. - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is no…

> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying. It can be implemented in a privacy-preserving way online: your government gives you tokens that prove that you are above age and that they provably cannot track. That's the exact equivalent. I believe that the other…

> and that they provably cannot track.

That's not easily provable though.

Any token given that way contains some amount of encrypted payload.

That secret payload may contain uniquely tracking numbers.

Even the encrypted payload itself, if treated as an opaque string, can be used for tracking if they decide to log it when they deliver it to you, and when the website where you use the token passes it back to the government auth service.

You need to replicate the UX of a stack of pile of cards at the grocery store, that's not really possible in digital space.

Post reply on HN