Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

101–110 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#101

Earlier quoted context omitted.

They don't, but there is a significant chance that their "security solution" uploads all the data to a cloud provider (Amazon, Google, Oracle) which will be more than happy to analyze the data for them.

That's possible but would be completely and highly illegal, the EU regularly fines companies violating GDPR, and those fines are not trivial at all, they can be quite hefty.

I was talking about the reality of the US, but even if I was talking about Europe: how does the GDPR even enter this equation here? I was never asked for consent to have my face recorded when I get into a shop in Germany. Were you?

Re: EU Age Control: The trojan horse for digital IDs

#102
post #90

Earlier quoted context omitted.

Yeah, imagine if every convenience store had CCTV security filming everyone 24/7. Oh, wait...

they don't know necessary who are you and what are you buying. I don't think also for big shops with many customers that techonology and reliably do instance segmentation - this is not face id.

Doesn't stop the stores from posting clips of you embarrassing yourself online and your acquaintances giving your name away for clout.

Re: EU Age Control: The trojan horse for digital IDs

#103

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

>You can already do that in the real world. This argument stays on the sand of inadequate analogy. The way that flaw is described in the story it allows industrialization of bypassing the feature. It's huge difference with the "real world".

And unlike in the real world, there's little to no real benefit to it online.

What value is there to industrializing any of this? Kids who will pay someone for their age tokens to watch porn or create social media would probably be smart enough to download a free VPN instead.

Even in the very worst case scenario for the designers of this system, where large amounts of people manage to extract their tokens and hand them out for free, the downsides everyone fears won't apply anymore. I think a lot of people might be happy about that.

Re: EU Age Control: The trojan horse for digital IDs

#104
post #83

Earlier quoted context omitted.

The difference you barely have to show you physical ID - mostly only when interacting with bank, signing document, government. I never got asked when buying alcohol and if asked at least I would only let to have a look instead of snapping a picture. Imagine if suddenly every grocery, pharmacy, petrol station, parking place, restaurant, bar etc. now would ask you for your ID AND would snap a picture and store in their…

Why would they? The only reasons to show ID I can think of is when watching porn or maybe when buying alcohol online, though I doubt stores will want to risk driving customers away with that.

Or using social media, signing up for any account where you can post content, and soon creating an account on your own device.

As for why would they, the same reason there are hundreds of tracking cookies on every site.

Re: EU Age Control: The trojan horse for digital IDs

#105

Earlier quoted context omitted.

>You can already do that in the real world. This argument stays on the sand of inadequate analogy. The way that flaw is described in the story it allows industrialization of bypassing the feature. It's huge difference with the "real world".

And unlike in the real world, there's little to no real benefit to it online. What value is there to industrializing any of this? Kids who will pay someone for their age tokens to watch porn or create social media would probably be smart enough to download a free VPN instead. Even in the very worst case scenario for the designers of this system, where large amounts of people manage to extract their tokens and hand th…

This "they'll just use a vpn" argument is infuriating to me because it's being used to downplay intrusive laws and make them more palatable. The obvious next step (the UK already hinted at it after the online safety act) is forcing VPNs to do ID verification.

Re: EU Age Control: The trojan horse for digital IDs

#106
post #91
post #84

Earlier quoted context omitted.

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

"They" will make it mandatory? Who is they? How will the current approach result in total surveillance? I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing. Can you explain to me, how with an eID one would be prevented from com…

> Can you explain to me, how with an eID one would be prevented from communicating with anyone or buying food?

Why did you only ask about eID and not about "inescapable digital currencies" that was also mentioned in the same paragraph at the top of the thread?

Re: EU Age Control: The trojan horse for digital IDs

#107

> Real cryptographic unlinkability schemes like BBS+ or CL signatures would produce uncorrelated proofs even on reuse. This is not that. This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+…

> Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives Yeah I'm getting really really tired of the "crying wolf" crowd

To be fair to some of them, across the Atlantic the Americans are implementing similar laws in absolutely ridiculous ways.

Many Americans don't even have ID (and plenty of those are reluctant to the general concept of any kind of government ID), let alone any kind of digital ID. However, their governments are pushing frankly weird and absurd ID verification laws to businesses online. Meta seems to be bankrolling lobbying around these laws, so whatever their game is, it's probably very bad for normal people.

If you're coming from a place where the government tells companies they need to set up a system or hire private companies to verify users' ages without providing any kind of official mechanism themselves, leading to ridiculous hacks from cheap and incompetent "age verification" companies, I can understand why the European system seems absurd.

If the US is going to adopt their weird age verification laws, the least they could do is fork the European system already laid out for them. Put a little American flag on it, call it "America First Christian Age Truthness" or whatever the people in charge like, but at least keep the basic privacy properties intact.

Re: EU Age Control: The trojan horse for digital IDs

#108
post #84
post #81

Earlier quoted context omitted.

I can't help but think people mean something else when they hear "digital ids" then what they are. Like I have a digital id from the government of the Netherlands that I use to log into their government systems to declare taxes or what not. I had an X509 certificate issued by Ukrainian government and have their app to do the same. It's bad somehow?

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

In Latvia we've had digital id for close to 20 years. Banks mostly use their own auth, some rely on digital id. No travel service has ever wanted me to use digital id, let alone any other kind of shopping. What we use it for is access to government resources, and signing digital documents. I trust this system WAY more than whatever some company comes up with.

Re: EU Age Control: The trojan horse for digital IDs

#109

Many countries have digital IDs for years now. It's not for digital IDs. It's for surveillance. Digital IDs are fine (and desired even) if you are only requiring it for GOVERNMENT (same entity that released them) communication. Push for age control is scheme to make that info available for private companies and that's the trojan horse here.

> that info

That info being: {"over_18": true} or maybe {"over_16": true, "over_18": false} with a government signature.

Might be a problem if you've got a Vatican ID, I suppose? Though they don't participate in this system of course.

Re: EU Age Control: The trojan horse for digital IDs

#110

Earlier quoted context omitted.

That's possible but would be completely and highly illegal, the EU regularly fines companies violating GDPR, and those fines are not trivial at all, they can be quite hefty.

I was talking about the reality of the US, but even if I was talking about Europe: how does the GDPR even enter this equation here? I was never asked for consent to have my face recorded when I get into a shop in Germany. Were you?

Security recordings fall into the category if legitimate need, and have to be deleted after a short while.
Post reply on HN