Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

191–200 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#191
post #92
post #85

Earlier quoted context omitted.

Punk rock has always been right wing. Libraries are about as far from this as they can get.

The anti-authoritarian, anti-government, anti-fascist, anti-capitalist music genre punk rock? Always right wing? I mean, Nazis have always been attracted to punk because they like the loud noise but are too stupid to understand lyrics, but they tend to get their shit kicked in by punks more often than not. I don't think that's the same thing.

I've seen a lot of confidently incorrect takes on this site, but "punk rock is right wing" may be the worst.

Re: The 'papers, please' era of the internet will decimate your privacy

#192

There will be your internet-connected computer which will be assumed to be compromised, & which little, if anything of use will be kept on, & then there will be the airgapped system you do work on, which will probably be the last trusted version of a Linux distro you have multiple copies stashed away of. It will be a very old-fashioned experience, & moving/sharing data will become a dicey business.

Renaissance of LAN parties and SneakerNets?

Re: The 'papers, please' era of the internet will decimate your privacy

#193
post #26
post #21

There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. Governments that are serious about age verification and individual privacy (which, doubtful they truly are) should agree on a protocol a…

>Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. If it's unlinkable, what's preventing someone from setting up a site that hands out anonymous tokens for anyone to use?

Yes, this breaks the whole scheme. Anyone promoting it as a solution is delusional. There's a triangle of "robust", "private", and "practical" and you can only pick two. This one omits robust. The various mitigations people might suggest in response will have to sacrifice one of the other dimensions.

Re: The 'papers, please' era of the internet will decimate your privacy

#194

Earlier quoted context omitted.

An enormous portion of the world is effectively addicted to a drug. Solution: Maximize the distance between yourself and the people

Rather than becoming a social outcast I’d rather support any proposed laws that take down the social media companies.

You can definitely drop social media and not become a social outcast. Group threads on Signal are great!

Re: The 'papers, please' era of the internet will decimate your privacy

#196

Earlier quoted context omitted.

The article talks about the possibilities of malicious cloning of these tokens by third parties, but fails to identify the much more common use case, and one that makes this scheme useless for age verification. It's one thing to be concerned about someone stealing my credential, but another to prevent the transfer of these credentials, especially if they are limited use credentials. The entire point of age verificati…

Yes, this is the part of the issue that is so frequently ignored: Anonymous age verification schemes are easily defeated through proxying because there wouldn't be any consequences for selling your tokens. "Install this app on your phone and we'll pay you $1 per day" and it will mint your anonymous identity tokens and send them off to kids who want to buy them. If there's no way to track the tokens, there is no possi…

I thought a solution to this would be to use a physical smartcard to store the certificate(perhaps on your government ID). if the protocol is a challenge/response and the private key never leaves the card it would make proxying without the physical card more difficult.

Re: The 'papers, please' era of the internet will decimate your privacy

#197

And we all know why lolberts are worried about kids and privacy online... Regret voting for Trump yet, chuds? You can't hide once we know who you are.

Have you ever heard the joke, how do you know if someone does CrossFit? Don’t worry, they’ll tell you

In my experience Trump supporters aren’t exactly quiet about it.

Re: The 'papers, please' era of the internet will decimate your privacy

#198

Earlier quoted context omitted.

> use of a persistent identifier at the terminus, yes. there is no other way to avoid the homeless problem you listed. by terminus I am referring to where a central authority vouches for unforgability. this does not mean advertisers will have a token they can use (see remote attestation infrastructure). > tied to a person whether or not the terminus can tie a token to a real world identity will depend on how careless…

> at the terminus, yes. there is no other way to avoid the homeless problem you listed. by terminus I am referring to where a central authority vouches for unforgability. this does not mean advertisers will have a token they can use (see remote attestation infrastructure). Where to even begin here.... To generate the token, it needs to be based on specific data. How do you prevent people from generating tokens based…

    > Look - I know you mean well, but it is clear from this discussion you aren't familiar with cryptography, system security guarantees, Internet infrastructure scaling, or what would be needed to introduce new descriptive information about a person on the Internet and not have it become a new privacy risk.
it's actually clear that you are the one who isn't familiar with this, I referenced remote attestation which you appear to know little about as it addresses the problem of identifying information (the service has no way to link tokens across without help from the CA).

you also don't appear to know what a nullifier is, in a ZKP system you submit identifying information and a hash of a secret string. the CA adds the hash to a public database and in the future you prove you one of the members of the database with a nullifier - the anonymity-set is everyone in the database who entered it prior to your submission. this can also be done with a blind signature to the same effect.

there is no further point to this discussion.

Re: The 'papers, please' era of the internet will decimate your privacy

#200
I think it was Ethan Zuckerman who once said that Congress is ill-equipped and incompetent to solve this kind of problem and that we need to design systems that guarantee outcomes and cites Signal as an example. We need to have that mindset now: a clarion call to software engineers.
Post reply on HN