Live data from Hacker News

EU Age Verification Project Mandates Hardware-Bound Attestation

linuxiac.com

51–60 of 206 posts

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#51
post #24

Earlier quoted context omitted.

That's a completely unhelpful, overly simplistic straw man argument. We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling add…

>> "We're creating gambling addicts (which is arguably the most harmful form of addiction)" --- I will need a source, because "arguably" is a very broad umbrella. "Arguably" heroin addiction is the most harmful addiction because heroin is the most addictive substance, clouds judgement and drives the addict to all manners of sociopathic behaviour (not only theft or prostitition)

One big difference is that heroin is mostly illegal or, if not outright illegal, decriminalized for personal use. Gambling is legal in most places, can be advertised quite freely and restrictions can be easily circumvented with crypto. Crypto casinos have little to no age verification and typically operate extrajudicially (from the victim). Gambling addiction has a high outcome of suicide and tends to leave financial ruin affecting not just that person but their entire family.

Heroin addiction was largely created by the criminialization of cannabis (the first so-called War on Drugs under Nixon) as a tool to persecute black people and war protesters and the overprescription of opioids (eg the Sacklers/Purdue).

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#52
post #24
post #18

All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.

That's a completely unhelpful, overly simplistic straw man argument. We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling add…

We must do something.

This is something.

Therefore, we must do this.

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#53
post #32
post #4

I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd. This isn't only a digital sovereignty issue, it's also an anti-competition issue.

My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws. Most analysts expect sites will offer multiple ways, for a variety of reasons. Eventually when the full EU Digital Identity Wallet is available age checks can be done using…

> Most analysts expect

Total bullshit.

There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.

The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.

Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.

This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#54

I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then... ...but then again, this is the EU, not the US.

Hardware attestation literally prevents that. That's why it's mandated.

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#55
post #28

Earlier quoted context omitted.

> We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc…

Any time I've been in an age-restricted venue here in Australia they have taken a picture of me and my ID at the door.

[deleted]

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#56
post #28
post #24

Earlier quoted context omitted.

That's a completely unhelpful, overly simplistic straw man argument. We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling add…

> We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc…

> You have no such guarantee when you upload government IDs to a server.

The problem is that so many people here look at this purely from a USA perspective.

An age check in many European requires no uploading of any ID. It’s an API call toward an ID service, it will tell you which data the service gets access to, and there’s strict regulations and liability around data retention.

I’m not concerned about the government. If they become authoritarian enough to worry, they will impose far tighter surveillance anyway. What we have now is the naive idea that just by not doing ID check, government surveillance is a solved problem in the free democratic world. It’s not. Avoiding ID checks just makes the problem worse because it makes the regular person complacent. The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked. Requiring audits of large corporations. Solutions that give corporations access to only the data they absolutely need and nothing else (the lack of such things is how we end up by uploading whole ID documents)

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#57

> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux. If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second)…

If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement. The key material must be DRM'ed, especially if some ZKP solution is used. Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Befo…

> If you want to actually enforce age restrictions

I don't.

This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#58
post #43
post #25

Earlier quoted context omitted.

What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors. It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to t…

This is the slippery slope fallacy and people in tech seem to love this argument. And you can argue in whichever direction you want with it. For example, "unfettered Internet access is just a series of tubes (shout out to Ted Stevens for that one) for pedophiles to rape your children." So now what? Is it your hyperbole against mine? The problem is that people are operating under a myth that they have anonymity. You d…

But in this case, the slipping just happened. This thread is about how an app that will be required for using a vast fraction of all websites will require hardware attestation and likely only run on closed, non-rooted mobile OSes. That's not a hypothetical scenario, it's literally what this thread is about.

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#59
post #24
post #18

All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.

That's a completely unhelpful, overly simplistic straw man argument. We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling add…

> So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed.

The market failure to provide an adequate solution wasn't natural. It was engineered by the tech companies and you are playing right into their hands. There is still a way to fix this from the root with software antitrust: force hardware vendors to ship their devices without an operating system.

Here's a more detailed explanation in a past comment about how the problem came to be in the first place, and why software antitrust can solve it:

https://news.ycombinator.com/item?id=49118578

Re: EU Age Verification Project Mandates Hardware-Bound Attestation

#60
It should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability).

That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.

Here's the expected timeline.

The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.

In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.

Post reply on HN