Live data from Hacker News

EU age verification app not planning desktop support

github.com

191–200 of 437 posts

Re: EU age verification app not planning desktop support

#191
post #160

Earlier quoted context omitted.

But you could do attestation on GrapheneOS, no need to require the users to have Google spyware preinstalled. Google is abusing its position here, attestation should be to verify the security model, not Google's business model..

Attestation is fundamentally incompatible with software freedom.

When scoped to attest the full software stack down to the kernel, yes, because it takes control away from the general purpose computing device that the user supposedly owns. I don't however have a problem with attestation scoped to dedicated hardware security devices such as Yubi Keys.

Re: EU age verification app not planning desktop support

#192
post #38

Tangentially, I would love to be able to see the age of everyone on the internet. IRL this gives us so much context when having an interaction.

And I hope they give their gender, ethnicity, nationality, religion, salary and geo coordinates.

right, because everything has to be a hyperbole. Either it has to be context-free or full totalitarian environment, right?

Maybe the internet was a mistake.

Re: EU age verification app not planning desktop support

#193
post #87

Earlier quoted context omitted.

I've been saying this for years: eventually not having your phone on you and powered up at all times will not be a crime, but it will be grounds for questioning and search. One day, there will be a knock on your door. "Good morning, this is the police. Is there something wrong with your phone? Is your phone broken? Can we provide you with a charge?" "No, I must have turned it off accidentally." "Can we assist you wit…

I think you're exactly right, and the groundwork is being laid today by the standards society is setting for everybody. People will assume a lack of phone or the presence of a phone but lack of usage / content on it, makes you guilty of some sort of crime similar to owning a burner phone. Tell somebody you use your phone less than 10 minutes a day and look at their face change.

> Tell somebody you use your phone less than 10 minutes a day and look at their face change.

While not less than 10 minutes per day for me, but I was having this argument on reddit over the iPhone Air - people couldn't fathom that there's someone out there that is not on their phone 24/7, and doesn't use their phone as their main computing device.

I clock in at under an hour screen time most days. It's the least ergonomic device for me to do anything remotely serious. Can't even stand typing on a virtual keyboard. My laptop is, and will remain, my main interface to the net and communication with others.

You'd think I was some kind of weird hermit luddite because of it.

Re: EU age verification app not planning desktop support

#194
post #129

Earlier quoted context omitted.

> you can't run your bank's app I can log in to my bank account using my desktop PC > government eID apps I can sign into government websites using my desktop PC and its smart card reader and my government-issued eID smartcard. No smartphone needed.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Which banks? Which country? How do they check and enforce iPhone / Google wrt. 2FA? Are you referring to TOTP as 2FA?

Re: EU age verification app not planning desktop support

#195
post #181
post #166

Earlier quoted context omitted.

But the bank and the horn content provider could collude and that would let the bank know that you're watching horn (shame, shame!). The ZKP approach aims to prevent this attack method.

Chase.com currently is using: mPulse Google Marketing Platform Meta LinkedIn Ads Trade Desk Aggregate Knowledge (Trans Union) Adobe Audience Manger Can you elaborate on how the risk of ironbank and hornpub colluding by de-anonymizing you via rainbow tables or IP forensics is substantially greater than Chase and PornHub using - Google Marketing?

It isn't, but due to bureaucracy, when designing a solution, it's that solution that has to be "secure" without really considering that the current outside situation is already insecure..

Anyway I'm not advocating for this solution, just addressing the question directly.

Re: EU age verification app not planning desktop support

#196
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Likewise in Sweden. No bank that I’m aware of is limited to require mobile only login.

Some neobanks are limited to mobile-only. The OP's statement was too general. It's also true that some regular banks are phasing out 2FA via SMS, which is outdated per EU regulations, and may not easily offer alternatives to their app for 2FA codes.

Re: EU age verification app not planning desktop support

#197

Earlier quoted context omitted.

Attestation is fundamentally incompatible with software freedom.

When scoped to attest the full software stack down to the kernel, yes, because it takes control away from the general purpose computing device that the user supposedly owns. I don't however have a problem with attestation scoped to dedicated hardware security devices such as Yubi Keys.

And if such dedicated hardware is ever required by the law, the manufacturer should be prohibited from bundling any business-related functionality there (such as displaying ads) that can't be turned off without breaking the certification.

Google's ad business model should never be mandated by law, unfortunately lawmakers seem to be unaware that this is what requiring Play Integrity effectively means.

Re: EU age verification app not planning desktop support

#198
I looked into the Swiss version of this, which is documented here: https://swiyu-admin-ch.github.io/

They faced the same question. Here is their answer: https://github.com/orgs/swiyu-admin-ch/discussions/20

The tldr is that they have a legal requirement to bind "verifiable credential shares" with the same human who got the e-ID originally, up to the current best practical technology. On Android, they judge that to be "keep the private key in the HSM and require a local biometric (or PIN) unlock to use it". This is why they argue that proving your age will not be possible without a mobile device.

You can prove your age anonymously, for anonymous account, which can be used on a non-mobile device. It's just that the proving the age part must happen from a mobile device.

À propos of more or less nothing: in the Swiss context, websites requesting the proof will be required to request the least information necessary for their need. They must NOT ask for your name, ID number, or birthdate if the question they are trying to answer is, "is this person old enough for our service?"

This is excellent technology, and the Swiss law on it that we are voting for next weekend is an excellent law, so I urge a OUI/JA/SI vote on it, if you're a Swiss citizen.

Re: EU age verification app not planning desktop support

#199
post #185
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Of course in the EU - pretty much all Baltic and Nordic countries support id cards connected via usb

Nope, Sweden requires Mobile BankID on iOS or Android for example.

Re: EU age verification app not planning desktop support

#200
post #164

I've posted this as a response but I'll post it again since it seems like a lot of people are confused about the project: This project is not THE digital wallet, it is an early prototype of the wallet (which can be criticized for what it is, but the issue is somewhat orthogonal). The actual infrastructure is not based on attenstation, if you read the guidelines (or the readme) they actually want to implement a double…

Thanks for chiming in! Is there some documentation on the Zero-Knowledge-Proof, that this app is supposed to use?

I don't know the specific ZKP variant if that's what you mean, but the general architecture of the system is best described in the 38C3 talk from earlier this year: https://www.youtube.com/watch?v=PKtklN8mOo0

There are some choices that are debatable (more on the issuer side iirc), but imho for the goals it has it's a competently made architecture.

Post reply on HN