Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

191–200 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#191

Earlier quoted context omitted.

To be fair to some of them, across the Atlantic the Americans are implementing similar laws in absolutely ridiculous ways. Many Americans don't even have ID (and plenty of those are reluctant to the general concept of any kind of government ID), let alone any kind of digital ID. However, their governments are pushing frankly weird and absurd ID verification laws to businesses online. Meta seems to be bankrolling lobb…

> Many Americans don't even have ID I don't believe this. "Many" perhaps in raw out-of-context numbers but as a percentage of the population, very few functioning, self-supporting and employed adults in America do not have an ID. It's simply not possible to participate in society without one. You need an ID to register a car, to drive, to vote, to bank, to get a job, to buy a house, to rent an apartment, to get water…

> It's simply not possible to participate in society without one. You need an ID to register a car, to drive, to vote, to bank, to get a job, to buy a house, to rent an apartment, to get water, power, gas, internet....

Around 10% of American adults do not drive.

6% of American adults do not have a bank account (4% for whites and Asians, 11% for Hispanic, and 14% for Black). It is 23% for people with incomes under $25k [1].

About 20% of adult Americans who are not retired do not have a job [1]. Did you forget that some people live with other people and in many of those arrangements only one of them has a job?

Many people have living arrangements where they are not the owner or the renter of record of the place they live. For example many people who live with others as described above.

Approximately 5% of the US economy is cash based and often does not care whether you have any formal ID. Often people who live mostly in the cash economy live in areas with many other such people, which makes it easier.

[1] https://www.cnbc.com/2024/08/02/23percent-of-low-income-amer...

[2] https://www.minneapolisfed.org/article/2022/whos-not-working...

Re: EU Age Control: The trojan horse for digital IDs

#192
post #90

Earlier quoted context omitted.

Yeah, imagine if every convenience store had CCTV security filming everyone 24/7. Oh, wait...

they don't know necessary who are you and what are you buying. I don't think also for big shops with many customers that techonology and reliably do instance segmentation - this is not face id.

Sure - that's saved for Visa or Mastercard to track your purchase history across time

Re: EU Age Control: The trojan horse for digital IDs

#193
post #173

Earlier quoted context omitted.

Or, I should say, things are enforced after the fact, through the possibility of criminal charges or civil lawsuits. Enforcement doesn't mean that crime is made impossible, just that there is enough deterrent.

Except there isn't enough deterrent. The big companies are still mining user data, they are just forced to use some extra dark patterns to trick people into compliance. Would-be criminals are not going to stop being criminals because of the threat of fines. And TLAs are not going to wait for due process to acquire access to data legally. All that GDPR does is give the illusion that people are being protected and CYA…

You're veering way off-course here. This started from "I was never asked for consent to have my face recorded when I get into a shop in Germany. Were you?", to which I replied that those recordings are radioactive and nobody's allowed to do anything with them except for intelligence agencies. We're not talking about generic web tracking and dark patterns.

Re: EU Age Control: The trojan horse for digital IDs

#194
post #21

Earlier quoted context omitted.

I don't know if it has anything to do with changes in elections directly. My government has been talking for a while making the case that social media use makes us dumber, sadder, and more scared. I believe it's true that they also see that playing out in elections, but that's not where they want to solve a problem. Wouldn't it be strange if solving a problem didn't affect elections?

This has been noticeable since Tahrir square; I used to say that Twitter gives you a revolution whether you need it or not. But it's becoming increasingly clear how badly compromised the whole thing is with fake opinions and enemy propaganda. I don't like either of the options. I don't like control by the state, and I don't like control by mad billionaires. I don't like the far right cesspool of 4chan, but can't disa…

> I don't like the far right cesspool of 4chan, but can't disagree with their position that they shouldn't have to care about OFCOM.

While I agree with this statement, I thought there was some kind of requirement that OFCOM goes through a process like this before being allowed to ask for a domain to be blocked in the UK?

The latter is, I think, something OFCOM should be allowed to do with a restriction that it can only come after other options fail.

Re: EU Age Control: The trojan horse for digital IDs

#195
post #91

Earlier quoted context omitted.

"They" will make it mandatory? Who is they? How will the current approach result in total surveillance? I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing. Can you explain to me, how with an eID one would be prevented from com…

Are you kidding right now? Have you seen what's happening with ICE in the US? EU countries are just one effective social media campaign cycle away from the same policies. "It can't happen here" is foolish thinking. See also: CCP

Policies are the problem here, not tools.

Re: EU Age Control: The trojan horse for digital IDs

#196
post #83

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

The difference you barely have to show you physical ID - mostly only when interacting with bank, signing document, government. I never got asked when buying alcohol and if asked at least I would only let to have a look instead of snapping a picture. Imagine if suddenly every grocery, pharmacy, petrol station, parking place, restaurant, bar etc. now would ask you for your ID AND would snap a picture and store in their…

That's not now it works.

At least in my country, the ID app lets you generate 3 levels of QR:

Level 1: Just age (also shows a photo on the screen). This is what you would typically use to go in a club or buy alcohol.

Level 2: Adds Full name, birth date, validity date.

Level 3: All the data you can see on the physical ID card.

Re: EU Age Control: The trojan horse for digital IDs

#197
post #84

Earlier quoted context omitted.

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

> And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing. Not really. Government is not Big Tech. This happens with accounts of some tech companies precisely because they're private entities setting their own rules in the still wild "wild west" of the Internet. Governments set…

The worry is not, that tomorrow you will be locked out of life. The worry is, that it will happen gradually, over maybe 20, 30 years.

As always when information exists digitally and can be processed rather easily, there is a strong temptation to misuse it out of its original purpose. As always there is a high risk of information leaking at some point, especially when in the not that capable hands of big organizations and governments.

The worry is also the drift towards disabling people's IDs for even on of the things the GP listed, at some point for any reason. The one with the bank account for example seems not too unlikely. Say at some point they associate financial information with that id. Banks demand insight on this data on grounds of wanting to grant loans only to people with good history. Later on they don't even want to give you a bank account when you ask, because there is no gain in it for them, because your accounts in the past tended to not have a positive balance and maybe at some point you had solvency issues. Try getting a flat to live in without bank account. Try getting a job without bank account.

The point is, that while governments are not big tech, they are also not tiny friendly grandma Emma's village shop. There are still lots of incentives to misuse and mismanage data, while at the same time governments often do not pay competitive salaries as businesses and often attract a certain kind of people working with your data.

Also keep in mind, that so far basically every such system that was implemented in countries like Germany had severe security holes. Just read up on the "elektronische Patientenakte" for example, or the CCC and the initial eID security issues. Trust has been eroded so far, it is at level zero for the government to get such a thing done right.

Re: EU Age Control: The trojan horse for digital IDs

#198
post #194
post #21

Earlier quoted context omitted.

This has been noticeable since Tahrir square; I used to say that Twitter gives you a revolution whether you need it or not. But it's becoming increasingly clear how badly compromised the whole thing is with fake opinions and enemy propaganda. I don't like either of the options. I don't like control by the state, and I don't like control by mad billionaires. I don't like the far right cesspool of 4chan, but can't disa…

> I don't like the far right cesspool of 4chan, but can't disagree with their position that they shouldn't have to care about OFCOM. While I agree with this statement, I thought there was some kind of requirement that OFCOM goes through a process like this before being allowed to ask for a domain to be blocked in the UK? The latter is, I think, something OFCOM should be allowed to do with a restriction that it can on…

Oh, it's much more stupid than that: OFCOM can't block websites, I just checked and it's available on my phone right now. They've issued a fine to 4chan instead. Which they are ignoring.

Imgur have gone the other direction: they have voluntarily blocked the UK (!), which is very irritating when trying to browse Reddit.

There's certainly a process, but not a good one.

(separate from all this, the Internet Watch Foundation maintains a blocklist which ISPs voluntarily follow, of actual CSAM.)

Re: EU Age Control: The trojan horse for digital IDs

#199
post #141

Earlier quoted context omitted.

> And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing. Not really. Government is not Big Tech. This happens with accounts of some tech companies precisely because they're private entities setting their own rules in the still wild "wild west" of the Internet. Governments set…

Being banned from life due to a TOS violation is a real concern because it's already hard to do a bunch of things without a Google or Apple account. If Google and Apple can require a government ID to create such an account, it becomes very difficult to evade a ban. Options to get around that problem include regulating Apple and Google or mandating that essential services not require accounts with third-party provider…

> Options to get around that problem include regulating Apple and Google or mandating that essential services not require accounts with third-party providers.

I would call for both of these things, for independent reasons.

All providers who get relied on in this way should need suitable regulation, even for non-essential things like supermarket loyalty cards.

Apple and Google in particular are now too heavily associated with a government hostile to the EU, therefore the EU should as a matter of urgency ensure that essential services do not require them in particular, and the surest way to do so (and make sure no shenanigans happen with mergers) would be to mandate that essential services do not require accounts with any third-party providers. Not even the postal system or a telephone number, you should always have a viable fallback to some physical office which is open at reasonable hours and is in a reasonably accessible location.

Re: EU Age Control: The trojan horse for digital IDs

#200
post #91
post #84

Earlier quoted context omitted.

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

"They" will make it mandatory? Who is they? How will the current approach result in total surveillance? I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing. Can you explain to me, how with an eID one would be prevented from com…

Only that it won't stay at the minimum information. They will want more and more, with some thinly veiled greed for more info.

For example hotels: Some chains may think to advertise using fear mongering, claiming that their hotels are the safest, because they perform background checks based on the information from their customers' ID. You don't want that? Fine! Go elsewhere then! This is private property, if you don't agree to these ToS, you are not allowed to enter or rent rooms, sooo sorry! All you had to do is sign your privacy away here and then let us mine your data ... You don't have anything to hide, do you??

The issue is, that every single involved party from business to government has an incentive to get more data from this system. If there are no laws with guaranteed severe punishments for violations edged into our inalienable human rights and constitutions and those are properly followed up on, in addition to making it technologically impossible to extract more information than necessary, the system sooner or later will be abused.

Post reply on HN