Someone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea. State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
EU Age Verification Project Mandates Hardware-Bound Attestation
81–90 of 207 posts
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#82All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
Maybe I'm naive, but I think there's no deeper motivation. There are activists and politicians who really believe this is a cause worth fighting for.
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#83> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux. If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second)…
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement. The key material must be DRM'ed, especially if some ZKP solution is used. Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Befo…
Say you have a public service and a platform site (social media, gambling, whatever), and the user does authentication in a way that anonymously proves to the platform that they're of age while revealing nothing else, and without revealing to the public service what platform they're accessing. But the protocol requires some expensive data (token that provides access to a bond account) which anybody MITMing the protocol can obtain.
Then if Alice tries to sell her age verification abilities to Bob, the protocol could be designed so either Alice learns the negotiated key and can snoop on everything Bob does, or she has to let Bob do a man-in-the-middle over a channel and lose the ability to observe what's going on after the first key exchange; and then Bob can acquire the token and make use of it at a later time.
This is very handwave-ish, but I don't think such a protocol would be impossible to design.
Under normal use, Alice has no reason to drain her own bond account. But if she's selling to an anonymous crowd who might use the token at any time (hence she can't trace the traitor), some troll is eventually going to do it.
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#84All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
> All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason ... Maybe I'm naive, but I think there's no deeper motivation. There are activists and politicians who really believe this is a cause worth fighting for.
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#85Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#86Earlier quoted context omitted.
> All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason ... Maybe I'm naive, but I think there's no deeper motivation. There are activists and politicians who really believe this is a cause worth fighting for.
Maybe we should start by tracking their every movement to see if they enjoy
https://europeanpirates.eu/chatcontrol-eu-ministers-want-to-...
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#87Earlier quoted context omitted.
What could be tracked from phones back then compared to now is completely different. Phones are basically only called "phones" for historical reasons.
So what? Some things are exceptionally hard to track now (like e2ee messages) that were trivial to track back then. Every remote communication could only be had in the clear. Everyone was fine with that. Was the US in the 80s a surveillance state?
Today, and as things continue to progress with speech-recognition, LLMs, video recognition, etc. surveillance can be automated. It's looking conceivable to be able to process all communication population-wide in real-time. That would have been unimaginable back then.
Now, texts and calls today are only a small role of phones. For many people, it's their primary general computing device. It's how they interact with the world. It contains their entire digital life.
Couldn't look at your photo reels and videos, and diary, and every purchase you've ever made, every opinion you've ever said on a public space, every community you've ever interacted with, every location you've ever been in down to the room, from wiretapping a phone in the 80s.
> Some things are exceptionally hard to track now (like e2ee messages) that were trivial to track back then.
Can be easier than back then if stuff like chat-control comes to pass, because now the message can be obtained, processed and stored indefinitely in an automated fashion for everybody at once. E2EE becomes security theater for the most part.
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#88The most privacy-obsessed people on earth are now handing a detailed log to their entire digital lives over to a group of barely-elected 3rd party overlords as well as foreign companies and intelligence agencies (if you think this won't be instantly compromised, you're tremendously naive).
...AND at the same time this is cementing monopolies for foreign tech companies within Europe. A double whammy of self-harm.
There's something very bleak about couching this under the 90s-era "protect the children" narrative too, given ultimately most Europeans care so little about children that they've rapidly stopped giving birth to them and in many countries have outsourced all childcare to the state.
It's not even a believable cover story anymore.
It seems more like the European officials looked over at the Chinese Communist Party's authoritarian control over the internet and thought to themselves, "Wow, look how little push back they get to their policies online! I want to do big fancy projects with other peoples money and have no accountability or transparency too!"
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#89It does seem like an effort to connect all online activity to real-world identities.
Re: EU Age Verification Project Mandates Hardware-Bound Attestation
#90Earlier quoted context omitted.
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement. The key material must be DRM'ed, especially if some ZKP solution is used. Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Befo…
> If you want to actually enforce age restrictions I don't. This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.