Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

161–170 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#161
post #83

Earlier quoted context omitted.

But laws against selling/giving alcohol to minors are moderately successful at curbing teen alcohol use because they carry with them a risk of punishment that grows with the scale of the operation. If all it took was one adult who thought "kids should be allowed to drink if they want" to provide all the kids in the country with free booze and that adult had no meaningful fear of repercussions, the laws would be nothi…

That one adult could also just download and serve the content without an age gate. The security system on the original download seems irrelevant.

Sure, the big sites could also serve the content without an age gate, both would just have to have to avoid being found as they would be breaking the law that proscribed the age gate.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#162

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

It's a figure of speech called metonymy. I agree Brussels is not very precise, a better word would be Berlaymont to refer to the EU commission specifically as there are a lot of institutions that could be meant by Brussels (Belgian federal govt, Brussels regional govt, EU commission, EU parliament, EU council, ...)

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#163
post #152
post #130

Earlier quoted context omitted.

The assembly seats in Brussels, so the decision comes from Brussels (geographically). It doesn't imply that people from Brussels are the ones to decide, not everyone has the same idea anyways. Though, as citizens of a EU member state, they have some responsibility, at least indirectly.

Brussels is the seat of five governments: the city itself, the Brussels-Capital autonomous region, the Flemish Parliament and Government (luckily the Wallon Government seat is in Namur), the Belgian Federal Parliament, and the European Commission and Parliament. The "Brussels" metonym is probably the most ambiguous reference to a government body on the planet.

When discussed on an American tech forum, or even in Poland, it is fairly unambiguous though.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#164

Earlier quoted context omitted.

>Discord lost thousands of them, despite promising to delete them after age verification occurred (and then not doing so) This is misleading, yet everyone seems to repeat it. Discord's implementation of ID verification did not retain IDs. Reporting on this was so poor, but what appears to have happened was that people that failed age estimation / ID checks had to raise a support ticket and get manually reviewed. That…

This is a distinction without a difference. Users were assured their selfies would not be retained and they were. Discord then proceeded to lose those selfies to bad actors, after promising not to retain them. The incident has caused enormous distrust of all age verification systems, which were already starting in the mind of the community from a base level of skepticism. It's already highly invasive to take a photo…

Were users assured that the selfies they emailed to support would not be retained? I'm loath to defend the multimillion dollar corporation, but let's at least be fair.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#165
post #109

It would be possible to implement age verification in a way that would somewhat work and that would be to use the correct crypto on an government issued ID card. Crypto where the OS (or a website) can ask the card: "Is the holder of that card over X years old y/n?" and the card would just answer with a binary yes no question without exposing any other data while still checking the government signature. Obviously that…

> Crypto where the OS (or a website) can ask the card: "Is the holder of that card over X years old y/n?" and the card would just answer with a binary yes no question without exposing any other data while still checking the government signature.

This is the same as "What's the card holders age" by simply binary searching for it. A better way would be:

1. Have the card define the countries age access levels. (Example in Germany: >=16 [Beer/Wine], >=18 everything else)

2. The app can only ask: "Is [BEER] allowed for the card holder y/n?

This makes it immediately cross-legislative and protects the exposed data from meta analysis.

Edit: This would allow for self exclusion too. Make it possible for individuals to give up access to gambling/alcohol/tabacco/porn nationally.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#166
post #120

Earlier quoted context omitted.

I’m not sure you realise that this is a far more generic rhetorical phenomenon that encompasses all kinds of situations. Like referring to the FBI as Quantico.

Or Scotland Yard for the metropolitan police in london. They were commonly known by that name almost immediately after their founding in 1829. Perhaps the earliest example is Pharaoh. It originally referred to the royal residence.

TIL Scotland Yard is the Metropolitan Police. I thought it was its own thing named "Scotland Yard" for some reasons I never bothered to investigate.

Which kind of proves your point.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#167
post #43

Earlier quoted context omitted.

Exactly. "Age verification" is the "think of the children" marketing campaign for "identity verification". Governments don't like anonymity; it makes it harder to find those they consider enemies. But it's hard to market something people don't want and get no benefit from. So, you dress it up in fear and make it easy to villify people who argue against it.

Stop with the scaremongering. This is a reference app implementation that uses a detailed framework which explicitly has as a core tenet double blindness. The place you prove your age to has no idea about anything other than you being of age, and the thing you use to prove your age has no idea about where you're using that proof.

Why do I need to prove my age again?

Right because a child might get online with a phone or computer and see something bad.

I think you should take your own advice: >Stop with the scaremongering.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#168

Earlier quoted context omitted.

The alternative would be to just not do anything and to remove liability from Meta et al. In the world we live in, where competing interests already spent tens of billions to bribe/lobby the EU, we have to be realistic about it. This open source and transparent ZKP-based approach is extremely surprising to see, publishing a draft in advance and inviting the public to break it so it can be improved? Are you kidding me…

The main issue appears to be that as per the blueprint user MUST use one of the mandated handsets (iPhone or Android with pre-installed and privileged Google Services) and: - MUST use either Google or Apple account - must not be banned by the provider or sanctioned in the USA These issues have been flagged to the devs working on the blueprint since the inception, only to be handwaved away. Getting banned can happen r…

The technical specifications published online foresee publication of the app also on alternative android stores, but Linux phone users are missing out. Though I guess things could always be extended...

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#169
post #87

Earlier quoted context omitted.

Okay, so those parents can just not give their kids their phones, and everyone else can continue living life as usual without needing a fancy new way of telling websites how old they are

Giving your kid a gateway to every bad thing on the internet is not life as usual. It's incredibly recent, and I don't have shares in SSRI manufacturers, so I don't like it.

Having a smartphone at all also is incredibly recent, so by that logic we shouldn't let anyone have them. Alternately, maybe we can recognize that they haven't been long enough for any specific way of using them to be the long-term universal standard.

In the meantime, I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting. I literally don't have any stake in whether you give your kids access to your phone or not, and I don't make any claims that I would have any clue what the correct way to raise a kid is. That doesn't make it reasonable to have a policy that requires literally the exact people who aren't the ones that are ostensibly supposed to be protected by the system tracked by it.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#170
post #130

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

The assembly seats in Brussels, so the decision comes from Brussels (geographically). It doesn't imply that people from Brussels are the ones to decide, not everyone has the same idea anyways. Though, as citizens of a EU member state, they have some responsibility, at least indirectly.

>The assembly seats in Brussels, so the decision comes from Brussels (geographically).

Except that half the time the assembly seats in Strasbourg. https://en.wikipedia.org/wiki/Seat_of_the_European_Parliamen...

Post reply on HN