Live data from Hacker News

Discord's face scanning age checks 'start of a bigger shift'

bbc.com

141–150 of 448 posts

Re: Discord's face scanning age checks 'start of a bigger shift'

#141
post #129

Earlier quoted context omitted.

Transferring your age and a way to verify it to any third party is by definition a privacy violation. Doing so in a safe way is literally impossible since I don't want to share that information in the first place.

I feel like you could, theoretically, have a service that has an ID (as drivers license ID), perhaps operated by your government, that has an API and a notion of an ephemeral identifier that can be used to provide a digital attestation of some property without exposing that property or the exact identity of the person. It would require that the attestation system is trusted by all parties though, which is I think the…

Wouldn't this require the API provider to know that tbe citizen is connecting to the app? Grindr users might be squeamish about letting the current US admin know about that.

Re: Discord's face scanning age checks 'start of a bigger shift'

#142

Earlier quoted context omitted.

Many countries (including in the EU) already required ID to use a SIM card: https://forestvpn.com/blog/news/countries-sim-card-registrat... Funnily enough, when the Philippines did this, it was decried as a violation of human rights [1]. But usually, media are so silent on such things I'd call them complicit. One already cannot so much as rent a hotel room anywhere in the EU without showing government ID. [1] https:/…

You can buy (and top up) a SIM card without an ID in the EU.

That depends on a country and for once there is no visible pattern or usual suspects in who requires it or not

Re: Discord's face scanning age checks 'start of a bigger shift'

#143
post #130
post #2

Aside from the privacy nightmare, what about someone who is 18 and just doesn't have the traditional adult facial features? Same thing for someone who's 15 and hit puberty early? I can imagine that on the edges, it becomes really hard to discern. If they get it wrong, are you locked out? Do you have to send an image of your ID? So many questions. Not a huge fan of these recent UK changes (looking at the Apple E2E sit…

> what about someone who is 18 and just doesn't have the traditional adult facial features? This can be challenging even with humans. My ex got carded when buying alcohol well into her mid thirties, and staff at the schools she taught at mistook her for a student all the time.

I grew a beard when I was younger because I was tired of being mistaken for a highschooler its quite annoying to have people assume you are 15 when your 20. still regularly carded in my 30s

Re: Discord's face scanning age checks 'start of a bigger shift'

#144

Earlier quoted context omitted.

At least the ways that a corner shop verifies age don't have the same downsides as typical online age verifiers. They just look at an ID document; verify that it's on the official list of acceptable ID documents, seems to be genuine and valid and unexpired, appears to relate to the person buying the product, and shows an old enough age; and hand the document back. The corner shop has far fewer false negatives, far lo…

That's exactly how a digital ID system would work, and yet people argue against those all the time as well. Additionally, the corner shop does not have far lower data privacy risks - actually it's quite worse. They have you on camera and have a witness who can corroborate you are that person on camera, alongside a paper trail for your order. There is no privacy there, only the illusion of such.

By data privacy risks I meant the risk of a breach, compromise, or other leak of the database of verified IDs. No information about the IDs are generally collected in a corner shop, at least when there's no suspicion of fraud; they're just viewed temporarily and returned. Not only do online service providers retain a lot of information about their required verifications, they do so for hugely more people than a typical corner shop.

Also, corner shop cameras don't generally retain data for nearly as long as typical online age verification laws would require. Depending on the country and the technical configuration, physical surveillance cameras retain data for anywhere from 48 hours to 1 year. Are you really saying that most online age verification laws worldwide require or allow comparably short retention periods? (This might actually be the case for the UK law, if I'm correctly reading Ofcom's corresponding guidance, but I doubt that's true for most of the similar US state laws.)

Re: Discord's face scanning age checks 'start of a bigger shift'

#145
post #140
post #138

Earlier quoted context omitted.

How are the certificates issued?

https://certisfy.com/partnership/ Any number of entities can be certificate issuers, as long as they can be deemed sufficiently trustworthy. Schools, places of worship, police, notary, employers...they can all play the role of trust anchor.

interesting idea...

how do you handle revocation when people inevitably start certifying false information?

Re: Discord's face scanning age checks 'start of a bigger shift'

#146

Earlier quoted context omitted.

> Parenting is a good solution Yes, to most of society's problems. Yet they persist.

So? They equally persist in the face of endless laws, I don't see how it follows that piling more laws on top is a better idea than deferring this to parents.

Parenting was the answer to kids not wearing their seatbelt, and getting maimed and killed by very survivable accidents. Simply teach your kids to wear their seatbelt. Yet seatbelt laws reduced fatality (8%) and serious injury (9%) in kids. It follows that "piling" such a law "on top", one that people decried as unconstitutional, was a better idea than deferring to the parents.

https://www.nber.org/system/files/working_papers/w13408/w134...

Re: Discord's face scanning age checks 'start of a bigger shift'

#147

Earlier quoted context omitted.

I feel like you could, theoretically, have a service that has an ID (as drivers license ID), perhaps operated by your government, that has an API and a notion of an ephemeral identifier that can be used to provide a digital attestation of some property without exposing that property or the exact identity of the person. It would require that the attestation system is trusted by all parties though, which is I think the…

Wouldn't this require the API provider to know that tbe citizen is connecting to the app? Grindr users might be squeamish about letting the current US admin know about that.

ICAO compliant ID cards (aka passports) and many national ID cards already are smartcards with powerful crypto processors.

Hand out certificates to porn, gambling or whatever sites, that allow requesting the age of a person from the ID card, have the user touch their ID card with their phone to sign a challenge with its key (and certificate signed by the government), that's it.

Government doesn't know what porn site you visited, and porn site only gets the age.

Re: Discord's face scanning age checks 'start of a bigger shift'

#148
post #140

Earlier quoted context omitted.

https://certisfy.com/partnership/ Any number of entities can be certificate issuers, as long as they can be deemed sufficiently trustworthy. Schools, places of worship, police, notary, employers...they can all play the role of trust anchor.

interesting idea... how do you handle revocation when people inevitably start certifying false information?

The app allows for self-revocation using the private key or a revocation code given when cert is issued, this is useful if a certificate is compromised...there is also an admin interface a trust anchor can use to revoke certificates they issue, a rogue trust anchor chain can also be revoked.

Re: Discord's face scanning age checks 'start of a bigger shift'

#149
post #133

I would like to think there there is a solution that can be engineered, in which a service is able to verify that a user is above an appropriate age threshold, while maintaining privacy safeguards, including, where relevant, for the age-protected service not to be privy to the identity of the user, and for the age verification service to not be privy to the nature of the age-protected service being accessed. In this…

There is a solution and I am the developer: https://news.ycombinator.com/item?id=40298552#40298804 Talking about it or explaining it is like pulling teeth; generally just a thorough misunderstanding of the notion....even though cryptographic certificates make the modern internet possible.

I don’t get it. What is to prevent a 9 year-old from buying a certificate and using it?

Re: Discord's face scanning age checks 'start of a bigger shift'

#150
post #129

I would like to think there there is a solution that can be engineered, in which a service is able to verify that a user is above an appropriate age threshold, while maintaining privacy safeguards, including, where relevant, for the age-protected service not to be privy to the identity of the user, and for the age verification service to not be privy to the nature of the age-protected service being accessed. In this…

Transferring your age and a way to verify it to any third party is by definition a privacy violation. Doing so in a safe way is literally impossible since I don't want to share that information in the first place.

> Transferring your age and a way to verify it to any third party is by definition a privacy violation.

No it's not. Unless...

> Doing so in a safe way is literally impossible since I don't want to share that information in the first place.

...well then it is.

But it's not constructive to claim that proving your age to someone is by definition a privacy violation. If someone wants to prove their age to someone, then that's a private communication that they're entitled to choose to make.

It is true that if technology to achieve this becomes commonplace, then those not wishing to do so may find it impractical to maintain their privacy in this respect. But that doesn't give others the right to obstruct people who wish to communicate in this way.

Post reply on HN