Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

151–160 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#151
post #78

Earlier quoted context omitted.

Parents taking responsibility for their kids. I grew up in a neighborhood full of drug dealers. Street sellers, not the classy Walter White kind. Ironically being on a computer all day kept me out of trouble. But with these laws in place I guess you might as well start doing stupid ish in real life.

The thing is, those dealers can end up in jail for selling drugs. More to the point, if a kid walked into a convenience store and the clerk sold them a pack of cigarettes, the clerk wouldn't get off the hook by claiming, "well, the parents are responsible for their kids." I'm also not sure how one would justify holding parents legally liable for crimes they played no role in committing. I'm not saying that I agree wi…

>I'm also not sure how one would justify holding parents legally liable for crimes they played no role in committing.

This is already a thing.

https://www.bu.edu/articles/2024/charging-parents-for-childs...

Once upon a time they idea that Americans would surrender all of their God Given rights for an illusion of security was considered absurd, but that's where we're at.

Re: The 'papers, please' era of the internet will decimate your privacy

#152
post #21

There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. Governments that are serious about age verification and individual privacy (which, doubtful they truly are) should agree on a protocol a…

I don't think they are serious about privacy and even if they were I don't even want to distinguish between "children" and "adults" on the internet. Things seem to have worked fine up to this point, there doesn't appear to be a public demand for age verification, rather some murky corporations/NGOs/agencies pushing for this. I think it's pretty clear there is some other intention besides protecting children that is t…

We should only need to distinguish devices with parental controls turned on from other devices, and rely on parents to set up the devices accordingly.

Re: The 'papers, please' era of the internet will decimate your privacy

#153
post #106

Earlier quoted context omitted.

There is a much easier solution that already exists - parental controls on children's devices. I honestly don't understand why is it not solving the problem? Yes, parents are responsible to set this up. But parents are also responsible to lock their alcohol, drugs or guns, condoms, etc., and many other things. Perhaps parental controls are not good enough? That's where the regulation could genuinely help - require ch…

I don't understand why the act of buying internet access isn't considered a parental control. I doubt very many kids are doing it or can. Ok, but parents buy internet access and then let their kids use it, because the kids need it for school. So? The parents job is to keep their kids out of trouble. Learning how to keep track of what their kids access shouldn't be difficult, and maybe should be part of the obligation…

The problem with this idea is that it assumes responsible parents, which are not a given. I agree with you completely - I don't want any kind of controls on the Internet - but we live in a world where we cannot actually rely on parents to fulfill what you would consider to be basic and reasonable expectations of parental duties.

Re: The 'papers, please' era of the internet will decimate your privacy

#154
post #106

Earlier quoted context omitted.

There is a much easier solution that already exists - parental controls on children's devices. I honestly don't understand why is it not solving the problem? Yes, parents are responsible to set this up. But parents are also responsible to lock their alcohol, drugs or guns, condoms, etc., and many other things. Perhaps parental controls are not good enough? That's where the regulation could genuinely help - require ch…

That's not the problem governments are solving. They're solving the problem of convincing the public it's a good idea to end the anonymity of internet use.

That's why they are still appealing to sentiment rather than established research (which actively refutes the arguments they are making).

Re: The 'papers, please' era of the internet will decimate your privacy

#155
post #94

Earlier quoted context omitted.

> I've also always been curious how a truely anonymous identity verification could possibly work. You go to a store. You show the clerk your id and give him a quarter. The clerk pulls a scratch-off ticket from the front of a ticket tape. The ticket contains a token identifier. It's anonymous. The clerk or his POS system knows your name and age, but doesn't know your number. The vendor providing the tape doesn't know…

> It's anonymous. The clerk or his POS system knows your name and age, but doesn't know your number. What prevents a commercial "AI" security camera analysis firm from doing a decent job of linking footage of a store's customers to a likely subset of tokens, based on the knowledge of which tokens are sent to which store and how many tokens have been pulled off of the roll so far? Remember that you can design the toke…

I’ve worked in the industry, so just adding some extra info, as I agree with you that the ticket system is not really less tracked than other systems, just differently tracked:

Lottery tickets don’t “fall off of trucks” or get “lost in the mail” because they aren’t valid for redemption until they’re activated at the POS terminal of a licensed store, and the lottery company knows which store receives each ticket roll, because they are shipped to known locations with tracking numbers and delivery verification and/or delivered in person by lottery employees. Even the rolls of blank lottery ticket receipt paper have different serial numbers every few inches, and it’s forbidden by policy to swap receipt paper between stores. All of these things are audited both regularly and randomly by state lottery officials.

Re: The 'papers, please' era of the internet will decimate your privacy

#158
post #57

Earlier quoted context omitted.

> Even on Hacker News the consensus is mostly in favor of anything from age restriction to making all social media illegal. That doesn't sound right. Put up a poll. I'd put money on 90%+ choosing some flavor privacy/anonymity on the internet.

The main issue is that they are very careful not to frame it like that. In broader contexts, it's always framed as something like "do you favor limiting children's access to social media" without a word on what it would cost to actually institute such a ban.

Yeah, and we’re starting to inoculate people against that kind of rhetoric. It’s a process.

Re: The 'papers, please' era of the internet will decimate your privacy

#159

Earlier quoted context omitted.

Wait - so you're advocating for use of a persistent identifier tied to a person? How is that any different than what advertising networks do right now beyond giving them additional guaranteed information of your age bracket? To clarify - it's not cryptographically necessary to present the same token for each and every transaction and serves to categorically defeat the entire privacy guarantee of ZKP. It also makes it…

> use of a persistent identifier at the terminus, yes. there is no other way to avoid the homeless problem you listed. by terminus I am referring to where a central authority vouches for unforgability. this does not mean advertisers will have a token they can use (see remote attestation infrastructure). > tied to a person whether or not the terminus can tie a token to a real world identity will depend on how careless…

> at the terminus, yes. there is no other way to avoid the homeless problem you listed. by terminus I am referring to where a central authority vouches for unforgability. this does not mean advertisers will have a token they can use (see remote attestation infrastructure).

Where to even begin here....

To generate the token, it needs to be based on specific data. How do you prevent people from generating tokens based on fake data and submitting that to the "terminus" that you mention? We already have cases of people bypassing facial scan liveliness checks for banks using AI-generated footage.

What about validating tokens during the token enrollment process based on your government ID? Though that makes sure that poor or undereducated people who don't have such an ID are locked out of large swaths of Internet services.

Though there's also the matter of it being trivial to generate fake IDs using AI.

If you have no gatekeeping for the token enrollment process, anyone can submit an arbitrary number of new tokens.

And if you do have gatekeeping, you're right back to square one of needing to validate against more than just your age.

After all - the cryptography algorithms will be publicly known. If the only thing ZKP is validating against is age, it won't take long to figure out how to generate identifiers based on fabricated information.

> whether or not the terminus can tie a token to a real world identity will depend on how careless the user was and how much collusion there is between the terminus and the services. at the very least it will impose an investigation cost.

No it won't. A user submits a token to a server. The user also logs in with their e-mail address or phone number. Their email and/or phone number is hashed and it, along with the ZKP token and any additional information the website has on you, will be sent to data brokers.

This is the same as any other bit of information out there that data brokers collect on the internet. They just associate your new info with other info you are required to provide in order to use various services.

This will be automated and will cost next to nothing for data brokers to take advantage of.

> contrast this with the situation as it currently is (under ideal assumptions) where a central authority verifies your real identity and issues temporary rate limited tokens which are then saved by each service and can at any time be linked to you whenever the central authority can get the service to disclose the database entry. the nullifier will force the central authority to do an investigation about who the nullifier actually belongs to which may actually fail.

....what? What investigation by central authorities? You are talking of a system that would constantly mediate permissions for billions upon billions upon billions of devices across dozens of services and accounts per device.

You couldn't hire an army of people large enough to handle this and AI is infamously awful at detecting when a given image has been generated with AI.

> realistically I expect VPNs and Tor to just become more popular in response to such nonsense. I wouldn't be using government issued tokens for anything that isn't trivial to tie to your identity already: such as a personal bank access.

Their popularity would only rise in order to VPN into jurisdictions that don't enforce this. Assuming major websites don't just mandate age/identity verification for all new users regardless of jurisdiction just because it's easier and cheaper to apply one system to everyone.

Look - I know you mean well, but it is clear from this discussion you aren't familiar with cryptography, system security guarantees, Internet infrastructure scaling, or what would be needed to introduce new descriptive information about a person on the Internet and not have it become a new privacy risk.

This is an issue that has no tech-only solution. The specifics aren't just something to just figure out at a later date - the specifics are everything. And it's something that is enormously difficult to get right and extremely easy to get very, very wrong.

Post reply on HN