Live data from Hacker News

Hackers had a live feed of every ID verification company scanned for over a year

techdirt.com

221–230 of 263 posts

Re: Hackers had a live feed of every ID verification company scanned for over a year

#221
post #198

Earlier quoted context omitted.

I'm not feeling strongly about enforcement. The point would be to not have websites be liable if things go wrong, the way that breweries aren't responsible if some drunk teen drives to his death. Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky, but it doesn't mean that it shouldn't be banned.

> The point would be to not have websites be liable if things go wrong im mostly on board with that. > Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky alcohol bans are way easier to enforce. the internet is invisibly broadcast everywhere. most of my downtown & surrounding area has free wifi access. devices that can connect to the internet are also everywhere. phones, tabl…

Without a device that you need to get from a physical transaction you won't be accessing the internet, either.

There are all kinds of restrictions on alcohol now. They haven't been there since the invention of alcohol, though.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#222

Earlier quoted context omitted.

> think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account) It is not true. You can move passkeys between OSs if you have a password manager or an OS that has this ability. For example, I store my Passkeys in iCloud Keychain and I have them synced on all my Apple devi…

But you don't own your passkey. That's the biggest red flag. It's yet another wall by apple to prevent you from leaving their ecosystem

I think the OS is needed to sign the challenge, but the private key can be taken wherever. And passkeys are multiplatform. Not Apple-only, by a long shot.

And I suspect that most geeks, hereabouts, could set up their own signing system.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#223
post #221

Earlier quoted context omitted.

> The point would be to not have websites be liable if things go wrong im mostly on board with that. > Enforcement of banning alcohol for younglings (or drunk driving in general) is equally tricky alcohol bans are way easier to enforce. the internet is invisibly broadcast everywhere. most of my downtown & surrounding area has free wifi access. devices that can connect to the internet are also everywhere. phones, tabl…

Without a device that you need to get from a physical transaction you won't be accessing the internet, either. There are all kinds of restrictions on alcohol now. They haven't been there since the invention of alcohol, though.

[deleted]

Re: Hackers had a live feed of every ID verification company scanned for over a year

#224
post #190

Earlier quoted context omitted.

And then there's the problem of undocummented / illegal immigrants that the US has, which nevertheless can often get some state services and have enough ID to pass by. Because it's a political issue, nobody can either legalize or deport them without getting into the political quagmire that is immigration reform. In functioning ID systems (and not having or wanting one is a valid political position which both the US a…

I'm not quite sure what immigration has to do with a national ID system in the US. Seems like you just wanted to bring that up to be able to say "man that'd be so much easier if you got rid of all the immigrants" which it would have no impact either way on this particular issue Also on the rotating schedule thing, driver's licenses expire in the US, usually on a 5-10 year cadence. Replacing the physical cards was not…

isn't the immigrant question a real obstacle for political change towards fixing this problem? That we would have to come to some kind of consensus on what to do for illegal immigrants

Re: Hackers had a live feed of every ID verification company scanned for over a year

#225
post #123

Earlier quoted context omitted.

To where, the site requesting the verification? Now it is no longer zero knowledge.

No, to the ID to prevent abuse if the card get stolen.

Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key.

The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.

Your system effectively collects exactly the data ZKP is intended to protect.

Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#226
post #71

Earlier quoted context omitted.

Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.

But the government inherently has that data, as it comes from there. They're the ones issuing the IDs in the first place. Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.

I think the point is that if I have to use some system to tell the government "this is me", that's pretty much equivalent to the ID. It doesn't matter that they have the info already, it's that I now need to send them it in order to use the internet to like, file my taxes or send a message to my doctor or pay my electricity bill or any number of mundane things that aren't particularly worth the extra attack vector to try to protect against.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#227
post #20

Earlier quoted context omitted.

That was sarcasm.

Are you sure? It’s really hard to differentiate nowadays

I am the one who said it, and I am sure. You can go back through my comment history to find me getting into arguments many times against the idea of ID verification for internet use.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#228
post #5

This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet

I think there's a number of people reading this who clearly didn't detect the satirical nature of this single sentence. It's blunt and obvious, but even so...

Yeah, I thought it was obvious enough, but then again, I also seem to get a lot of disagreement every time I directly express the opinion that ID verification for internet use is a terrible idea, so I have no confidence which side the downvotes came from (maybe both!)

Re: Hackers had a live feed of every ID verification company scanned for over a year

#229
post #19

Earlier quoted context omitted.

This is precisely why the authority doing these checks needs to be the government that already issues the IDs . Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place . I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue…

> I don't know why HN rails against it [ZKP for age verification] constantly Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU sch…

> Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so.

As do physical IDs, as somebody who's bought his younger brother beers growing up.

Re: Hackers had a live feed of every ID verification company scanned for over a year

#230
post #226
post #71

Earlier quoted context omitted.

But the government inherently has that data, as it comes from there. They're the ones issuing the IDs in the first place. Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.

I think the point is that if I have to use some system to tell the government "this is me", that's pretty much equivalent to the ID. It doesn't matter that they have the info already, it's that I now need to send them it in order to use the internet to like, file my taxes or send a message to my doctor or pay my electricity bill or any number of mundane things that aren't particularly worth the extra attack vector to…

I think you're conflating a few things here.

With ZKP, you specifically don't have to do that. That's precisely what the Zero Knowledge in Zero Knowledge Proof means. Those are good for stuff like age checks.

But for the other stuff, of course you need to tell the government who you are??? How else are you gonna pay your taxes? Just send them some money anonymously and hope that settles it? Of course they need to know who's paying their taxes?

Post reply on HN