Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

181–190 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#181
post #99

It is "funny" to read every single time "to protect minors online" like there are no adult around them, while technically those technologies are by design to control every single human for online access. It is not because the words are well chosen to sound unpolitical, just for "security", that it make those law/technology not political. It is political.

Speaking of well chosen words. If you have to put "funny" between quotes at the beginning of a sentence, just tell us how you really feel. I fully understand the people who say it's all about control. I also understand why politicians feel they have to do something. My wife works with low IQ, low income and otherwise underprivileged kids. The completely unsupervised 'iPad' generation, if you will. There are no adults…

Let's take an example with a current project of law from Macron (french president):

"Some people can't support their health condition, and they should be helped to die". This end of life law is introduced like a care service for people having issue with health with no happy ending at sight.

The reality of the vision of Macron (liberale capitalist) is: All his actions are made to kill public health care, and aims to open the field to private corporate. People in need of bed at hospital are denied (public beds are getting more and more cut). People in need of teams for mental care are denied (public teams are getting more and more cut and overbooked). People in need are juste denied. They cant' pay? great, they can now legally choose death, it will be legal. Next client please. Everyone who can't pay doesn't need to feel a weight on his family/friend. Yay :/

This law is shown like a right of care, all the population can be legally targeted, while they could just have the right of health care and stay alive in decent condition. This could be another solution, but it doesn't meet Macron (and its sponsors) ultra capitalist's vision of open market.

Note: current concerned people are the first to call a big NOPE on this law.

I think you see where I go: I think you're highlighting a true and very important problem (I've worked 10 years with children, i confirm your point), but the current solution brings more issues than what it is supposed to solve, same for Macron's end of life law. Having a problem doesn't mean you have to risk the full society in a Orwellien way.

Sorry im not english speaking native, hope you understand more my feeling ?

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#182

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

Can you give a brief explanation of how this is done with a zero-knowledge proof? That site is low information and painful to navigate, and it seems quite surprising to me that this is possible. ID verification, in the government sense, is ostensibly going to require matching an ID against a some other resource. If done locally then you can trivially spoof the result, akin to hacking a game, but if done remotely then…

https://github.com/eu-digital-identity-wallet/av-doc-technic... has an overview of the protocol so far. Annex B has the details on using ZKPs.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#183

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

It definitely forces countries to do things they want to do, generally via compliant leadership of those countries. See the last 15 years of UK voters being worried about immigration levels, vs immigration levels.

> See the last 15 years of UK voters being worried about immigration levels, vs immigration levels.

Look, let's be clear here. The UK (as a member state) was concerned that the EU was becoming too federal. Therefore (following Machievelli) they decided to push for new members, mostly the eastern bloc countries.

Then, politically, it was difficult for them to refuse to allow immigration from those countries (many of the other members had a moratorium for a few years post-accession). This lead to lots of British people becoming very upset, at the EU for some reason (even though their government had done this).

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#184
post #120

Earlier quoted context omitted.

Or Scotland Yard for the metropolitan police in london. They were commonly known by that name almost immediately after their founding in 1829. Perhaps the earliest example is Pharaoh. It originally referred to the royal residence.

TIL Scotland Yard is the Metropolitan Police. I thought it was its own thing named "Scotland Yard" for some reasons I never bothered to investigate. Which kind of proves your point.

> TIL Scotland Yard is the Metropolitan Police.

It is not? But also it is.

You are right that when people say "Scotland Yard" they do frequently mean the whole Metropolitan Police. And you are also right that there is no other police entity (that I know of) which would be associated with that name.

But also, "Scotland Yard" was just the address of the original headquarters of the Metropolitan Police. Even then it wasn't the whole organisation, just the address of one of the buildings. Then they got a new headquarters and called it "New Scotland Yard". And to confuse matters further they repeated this multiple times. Which means there are 3 buildings which were called "New Scotland Yard" at various points in time.

And today of course the MET occupies far more real estate than just the famous "Scotland Yard". For example if you look at this FOI request[1] you can see that there were 226 other buildings the Metropolitan Police used in 2023. (Not counting covert/sensitive estate).

1: https://www.met.police.uk/foi-ai/metropolitan-police/disclos...

Scotland Yard was originally the name of the street in which headquaters of the Metropolitan Police.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#185

Earlier quoted context omitted.

TIL Scotland Yard is the Metropolitan Police. I thought it was its own thing named "Scotland Yard" for some reasons I never bothered to investigate. Which kind of proves your point.

> TIL Scotland Yard is the Metropolitan Police. It is not? But also it is. You are right that when people say "Scotland Yard" they do frequently mean the whole Metropolitan Police. And you are also right that there is no other police entity (that I know of) which would be associated with that name. But also, "Scotland Yard" was just the address of the original headquarters of the Metropolitan Police. Even then it was…

Right. What I meant is, until today I believed that "Scotland Yard" was an entirely different law enforcement agency from MET.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#186
The trouble here is not that the age checking is right or wrong but it would be unethical for anyone who has the competence to develop this kind of app to work on it because it is fundamentally unworkable -- it would be like me taking money from somebody to help them with their perpetual motion machine.

The kind of developer you are going to get is either going to be somebody who knows what time it is and cynically works on a project that they know is going to fail (unethical) or someone who is not going at it with "the end in mind" but is just cosplaying as a software developer (incompetent)

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#187

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

> The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. No it isn't. Literally that is not the scope document, and such a solution would not be permitted by the EU as compliant with the legislation. The app isn't zero knowledge. A prototype workflow has been designed for a one way transf…

The goal would be that neither the verification service nor the service you are verifying with can link the connection: the verification service can't tell which service you are connecting to, and the service you are verifying your age to can't determine your ID. The first two issues you mention don't necessarily seem to kill that (though I agree they are both suboptimal: once you are verified you should be able to generate your own verification keys without connecting to the verification service, and any requirement for attestation is just an unncessary restriction), though the revocation check does seem like it might be a problem.

The issue is that a lot of these services wave around a lot of words that _might_ mean that they are reasonably private, but it's damn hard to actually detemine if it is actually working like that in practice (the eIDAS standard seems to suggest the ZKP stuff is entirely optional, for example).

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#188

Earlier quoted context omitted.

Zero knowledge proofs are when the prover can prove the statement is true to the verifier without disclosing more information beyond the statement. It doesn’t mean the prover cannot talk to other systems to produce the statement.

That only works in the context of when the sender isn't the adversary, which isn't the case in an age verification system - it very much does treat the sender as the enemy and untrusted. And again, the revocation chain on the backend is not zero proof.

That's only an issue if getting the proof involves somehow identifying the service you are sending it to. If it's a generic 'send me a proof' it's not necessarily a problem, though of course it would be better if you could just generate your own proof.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#189
post #109

It would be possible to implement age verification in a way that would somewhat work and that would be to use the correct crypto on an government issued ID card. Crypto where the OS (or a website) can ask the card: "Is the holder of that card over X years old y/n?" and the card would just answer with a binary yes no question without exposing any other data while still checking the government signature. Obviously that…

in the Netherlands we have a better system called iDIN; it works like doing an online payment (iDeal / WERO): * Website asks for age verification * User is redirected to their bank * Bank asks the user to log in - username/password, 2fa, bank app (whose login is behind the device's security and a secondary verification like PIN code or biometrics) * Bank tells the requester that the user is 18+, no more This leverage…

This still gives your bank a pretty good idea of what websites you are visiting though. It should not need to know this with modern cryptography.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#190
post #4

"Let’s say I downloaded the app, proved that I am over 18, then my nephew can take my phone, unlock my app and use it to prove he is over 18." - and how is that something that could, or should, be addressed by the app? Are we even serious??

When there's severe downsides to an measure to try to improve something else, the efficacy of it matters. This isn't about the app specifically, it's about the requirement for this kind of verification in the first place.
Post reply on HN