Live data from Hacker News

Yoti age checks share facial photos and device fingerprints with third parties

techxplore.com

21–30 of 38 posts

Re: Yoti age checks share facial photos and device fingerprints with third parties

#21
post #18

If a city hires a cop who openly accepts bribes, it's a problem for city hall. If they tolerate crooked cops, they are rightly painted as being corrupt as well. If a government mandates age verification and tolerates companies like Yoti as enforcers of their law, it's exactly the same thing. If politicians aren't willing to see that new laws are enforced with integrity, then these corrupt politicians are the problem…

You're right but its not just the politicians unfortunately, one of the main reasons the general population isn't acutely aware of these kinds of occurrences(Yoti is not the only culprit) is because major news outlets don't give these stories the time of day. If were putting blame on politicians for their contributions to this problem we should also do the same for political news outlets. If they had a shred of moral decency and weren't corrupt they would allow and want this news to spread openly.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#22
The third-party list on page 12 is not small. The real-time api architecture creates a live, per-query link between a specific user event and every broker in the chain. Batch transfers or delta shares would break that linkage. Zero-knowledge proofs (also mentioned in the study) can prove age without handing anyone a name, document, or photo.

There's no reason Aristotle or Veratad should see who the underlying requestor is. Yoti should receive the verification request, strip the context, make the request - that's it. The fact that it isn't structured that way and they are tagging on additional metadata suggests per-query economics, which creates a direct incentive to route more verifications through more parties, exactly backwards from data minimization. I'm not going to call it a rev share, but the architecture is consistent with one.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#23

The third-party list on page 12 is not small. The real-time api architecture creates a live, per-query link between a specific user event and every broker in the chain. Batch transfers or delta shares would break that linkage. Zero-knowledge proofs (also mentioned in the study) can prove age without handing anyone a name, document, or photo. There's no reason Aristotle or Veratad should see who the underlying request…

While I agree with your claim that it is likely the number of third parties info is being routed to is likely related to per-query economics, I want to note that ZKP are not magic. They tend to either be worthless at preventing fraud or require so much additional context as to question how much privacy is really being preserved.

While ZKP is more useful in limiting how much info is provided and, depending on implementation letting you make sure of the full scope of information acquired....if it literally only validates age then there's nothing other than logistics preventing a single adult from authenticating the entire world.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#24
post #5

I've been telling people for years now not to engage with systems such as these. Some say I'm just being paranoid. But a growing number concerningly reply with either "So? What are they gonna do with it?" or "They already have it, it doesn't matter." Normal people either don't know the dangers present or they don't understand that stopping the flow hurts the machine. And they want neither to know or understand. Apath…

But what is the alternative? Many of these systems are added to digital wallets due to legal requirements or fraudulent cases. For example, one case of fraud that I’m aware of happened in Chile, where citizens were able to open bank accounts digitally with just their ID. But since there is no good biometric information, many criminals took the IDs of homeless people to open accounts and move money around. Sadly, thes…

I recall at an old place of work, the security office having a poster on the wall that said something to the effect of "if your facial biometrics get compromised, you must change your face".

Silly as they were trying to be, the concept still holds -

Facial biometrics can and do get compromised too. Your example of IDs taken from the homeless - what the heck prevents organized criminals from taking pictures or recordings of their faces too?

Already there's malware out there stealing facial recognition data from infected devices (ESET reported on this nearly two years ago). Unlike changeable passwords, once your facial recognition data is compromised then that's it. Scammers can now impersonate you on top of having defeated this additional layer of fraud prevention.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#25

The third-party list on page 12 is not small. The real-time api architecture creates a live, per-query link between a specific user event and every broker in the chain. Batch transfers or delta shares would break that linkage. Zero-knowledge proofs (also mentioned in the study) can prove age without handing anyone a name, document, or photo. There's no reason Aristotle or Veratad should see who the underlying request…

While I agree with your claim that it is likely the number of third parties info is being routed to is likely related to per-query economics, I want to note that ZKP are not magic. They tend to either be worthless at preventing fraud or require so much additional context as to question how much privacy is really being preserved. While ZKP is more useful in limiting how much info is provided and, depending on implemen…

Totally agree. Was just trying to emphasize that there are better ways to do this if privacy and security are something that Yoti actually cares about. ZKP is not a magic bullet.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#26
Probably worth mentioning that I just did a very informal and quick review of identity/age verification providers because of payment provider requirements. Yoti came up as one of the more privacy focused (relatively) lower friction options because they only require a face scan and try to estimate age based on that. They may do more but that is as far as my research got.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#28
post #18

If a city hires a cop who openly accepts bribes, it's a problem for city hall. If they tolerate crooked cops, they are rightly painted as being corrupt as well. If a government mandates age verification and tolerates companies like Yoti as enforcers of their law, it's exactly the same thing. If politicians aren't willing to see that new laws are enforced with integrity, then these corrupt politicians are the problem…

You're right but its not just the politicians unfortunately, one of the main reasons the general population isn't acutely aware of these kinds of occurrences(Yoti is not the only culprit) is because major news outlets don't give these stories the time of day. If were putting blame on politicians for their contributions to this problem we should also do the same for political news outlets. If they had a shred of moral…

Why stop the logical chain there? The people are to blame for making garbage media more profitable than real news.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#29
post #17
post #15

Earlier quoted context omitted.

>not to engage with systems such as these Yoti is used by governments. Principled stances are all good and well for hn comments but eventually collide with reality

Governments, regardless of what threat they wield against those they supposedly govern, are limited by the fact that they are organizations run by humans. For now. God forbid we ever reach the point where there are no humans... Anyways, because of that they require humans to ensure enforcement. A major reason why Yoti is able to do what it's doing is because there are no humans enforcing privacy and data protection l…

An admirable principled stance that just doesn’t fucking work in the real world. Government processes and staff have zero interest in such stances. Next time you go through a border control try refusing to be searched or scanned on grounds of privacy and see how that goes for you.

Lay the chat about broken social contract and how governments are a threat thick enough and officials may decide it’s better if you’re not on a plane at all

Re: Yoti age checks share facial photos and device fingerprints with third parties

#30
We are definitely entering the era of stupidity. Who wrote that article hasn't read the paper, just asked some AI to scan it and fudge up an eye catching article. The article claim things that are not in the paper, that are actually false, the paper does state the face image is actually encrypted on the client side and never says that is shared with third parties. If you prompt your AI with enough bias and ask it to read a technical paper, then this is what happens. And given no one bothers to check facts there you go, everyone screaming against a legit company that is just doing its job. The paper itself reports that Yoti has given an amicus brief in a US court where they just stated that age verification can be done in a privacy preserving way (which seems to be what they do, they have nothing to gain from keeping data). I wonder if that is why they are after Yoti so badly now.
Post reply on HN