Live data from Hacker News

What we call "age verification" is actually mass surveillance

pluralistic.net

451–460 of 520 posts

Re: What we call "age verification" is actually mass surveillance

#451

Earlier quoted context omitted.

> The website only sees the ‘over_18’ attribute, which is backed by the government signature Not true. The device's public key is also sent, which functions as a stable device identifier. We've spent years trying to get away from stable tracking IDs and fingerprinting. Returning to a system where devices are sending a stable ID to a website to prove ownership is a step backward. There are proposed mitigations like is…

> Not true. The device's public key is also sent, which functions as a stable device identifier. This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. The wallet will automatically request new credentials in batches…

The government will, of course, log all issued public keys and who they belong to.

Re: What we call "age verification" is actually mass surveillance

#452

Earlier quoted context omitted.

> Not true. The device's public key is also sent, which functions as a stable device identifier. This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. The wallet will automatically request new credentials in batches…

> The wallet will automatically request new credentials in batches when they run out. Is that an ongoing cost that I’ll pay for via taxes? It doesn’t matter how anonymized all the schemes are. The government needs to give permission by signing attributes. It will be abused to gate everything we can do. I wouldn’t be surprised if everything is gated behind attestation fairly quickly. Then our “secure” devices will att…

Whatever the system is taxes will pay for it and the inherent cost will not be very high, but it'll be contracted to a greedy money-wasting government contracting firm like Oracle, as always happens.

Re: What we call "age verification" is actually mass surveillance

#453

Earlier quoted context omitted.

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

> The government issues an eID to your wallet I'll stop you right here. I don't want to be forced to use a government issued ID — one the administration can revoke at a whim, one that will certainly be backdoored by intelligence agencies including the ones they haven't told you yet — just so I can talk to my friends online. It's insanity that we are asking the state to regulate personal identity — and trust them with…

Don't you have a SIM card?

Re: What we call "age verification" is actually mass surveillance

#454
post #360
post #268

Earlier quoted context omitted.

Which part of that is avoiding the distopian control? the very first line, government issued digital id - we have been avoiding that for a very long time how does this work on an open source operating system?

> Which part of that is avoiding the distopian control? Your ID is already controlled by your government, and we don't call that dystopian control. With privacy-preserving age verification online, the government doesn't learn what you do with the cryptographic token that proves that you are old enough, and the website doesn't learn who you are. So it's exactly the same situation as today, except that now there is age…

The California age "attestation" system is a really good idea. It just delegates to the device owner, assuming anyone who can buy a device is the parent or is close enough to being an adult it doesn't matter. And then it makes using any other signal illegal unless you're a bank.

Re: What we call "age verification" is actually mass surveillance

#455

Earlier quoted context omitted.

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

How does this work without a phone? I do 99% of my computer work, like now, not on a phone. Do regular desktop and laptop computers have the same secure enclave feature?

No you just can't do it there. Scan a QR code on your phone.

Re: What we call "age verification" is actually mass surveillance

#456
post #381

Earlier quoted context omitted.

> I, who don't have or plan to have children, should spend my money to protect other people's children from the Internet. For the same reason your taxes pay for schools even when you don't have kids. Because we live in a society. If you struggle to understand why that matters without reference to more direct personal stakes for yourself, just know that without a society, the children will grow up to rape you, kill yo…

>For the same reason your taxes pay for schools even when you don't have kids. >Because we live in a society. Quote attributed to attributed to Jiddu Krishnamurti 'It Is No Measure of Health To Be Well-Adjusted to a Profoundly Sick Society' >just know that without a society, the children will grow up to rape you, BS. I can tell you that you have never lived in a 'society' where there were no taxes. I have. Have more…

> I can tell you that you have never lived in a 'society' where there were no taxes. I have.

Bet ya haven’t

Re: What we call "age verification" is actually mass surveillance

#457

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

Congratulations, you just outlawed open computing thus still getting us into the coming dystopia. This is not an acceptable solution especially to a problem that doesn't really need to be solved by age verification.

Re: What we call "age verification" is actually mass surveillance

#458
post #358

Earlier quoted context omitted.

The government still gets to know what you're doing online. How is that privacy?

Nope they don't. That's the whole point of privacy-preserving age verification. Technically it is possible. The complaint that people have is that they don't trust that any government will get it right. But it is technically possible with known cryptography.

No, it isn't technically possible. With true anonymity you can also re-sell tokens making them meaningless. If you prevent token sharing then you cannot have real anonymity. You can't have your cake and eat it too.

And if you have to trust the government to get it right then you have already lost because they are definitely motivated to NOT get it right because they WANT to track you.

Re: What we call "age verification" is actually mass surveillance

#459

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

> Could you be more specific as to what you're imagining? sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic. - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is no…

> - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.

Until it is because the store keeps records of who they sold which cards to.

Re: What we call "age verification" is actually mass surveillance

#460

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

I don't want an eID established on the net. It isn't sensible design. It would only work for the legal offerings and those just can send a header and devices need to block any communication if device is in kidmode. Easy, efficient, better engineering.

Illegal offerings won't do either of course. That can only be achieved by whitelisting a kid-net. Resource intensive, but only choice if you want unsupervised kid safety on the net. Because the net isn't kid safe and it cannot be by design. So you would need to create a subnet with actively moderated content.

Any other proposed mechanism has severe flaws. The only other choice is active parenting, which is unrealistic. An internet ID solves nothing, but creates more problems.

Post reply on HN