And again, there will be no monetary consequences for the companies that failed to secure our private data.
And governments will continue to force citizens to use these shitty companies for whenever they need id verification.
Hackers had a live feed of every ID verification company scanned for over a year
81–90 of 263 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#82Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
It's been released and in production since summer. Since then, several social networks have apparently started A/B testing age verification for their EU users, but how many of them actually integrate with the anonymous solution that is now available and in production? To my knowledge: 0. They all use Persona.
This highlights one of my main criticisms of EU's naive approach to regulation of tech companies. They fail to realize that any regulation that they impose will be complied with in the most malicious way possible, which is how we got cookie banners with dark patterns instead of a simple HTTP header saying no thanks to cookies.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#83Earlier quoted context omitted.
As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…
I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#84Earlier quoted context omitted.
Passkey?
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
It's not all sunshine and roses, though. Despite having Bitwarden set as the only passkey provider in my Android setup, the phone persistently only offers me Google. Which is empty, because as I said, I won't use one tied to things I can't control. Works great on desktops, though.
Passkeys can theoretically require you to be on hardware, I haven't found anything yet that requires that.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#85Earlier quoted context omitted.
Concrete ZKP age verification schemes are hardly zero knowledge. Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy. Now little Johnny borrows my ID, and uses it to setup some oracle that provide…
add MFA to the check
Re: Hackers had a live feed of every ID verification company scanned for over a year
#86Earlier quoted context omitted.
Passkey?
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default.
As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wouldn't work for passkeys. Every website with passkey access I've used so far makes passkeys optional and forces you to set a password already. If they switch their default to passkeys and add a password as an optional step, nothing would change.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#87Earlier quoted context omitted.
I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.
I understand the sentiment, but your government you can actually fix by voting. If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#88This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
Re: Hackers had a live feed of every ID verification company scanned for over a year
#89Earlier quoted context omitted.
As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…
> increasingly fascist chauvinist nationalist drifting in the geopolitical landscape What's going on in France?
Re: Hackers had a live feed of every ID verification company scanned for over a year
#90Earlier quoted context omitted.
> increasingly fascist chauvinist nationalist drifting in the geopolitical landscape What's going on in France?
France has always been chauvinist and nationalist. The principle reason why the Netherlands joined the EU was to sabotage the French-German alliance- all the alarm bells went off in the 1950s.