Live data from Hacker News

EU age verification app not planning desktop support

github.com

201–210 of 437 posts

Re: EU age verification app not planning desktop support

#201
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Which banks? Which country? How do they check and enforce iPhone / Google wrt. 2FA? Are you referring to TOTP as 2FA?

All of them now require some kind of 2FA, everywhere. This is due to a legal requirement on all EEA payment providers that they require 2FA for almost everything since 2020, including accessing your account on their website: https://en.wikipedia.org/wiki/Strong_customer_authentication

TOTP codes would be allowed by the regulation, as would biometric approaches or separate physical tokens, but in practice every bank I've used in recent years (quite a few, mostly Spanish but also in Belgium & Switzerland) require that you accept a confirmation prompt or similar in their app.

Re: EU age verification app not planning desktop support

#202

> At present the project is focused on mobile platforms, specifically Android and iOS, as they cover the vast majority of users and real-world use cases. (..) Desktop support is not currently within the project's scope. This is the equivalent of a "Do you guys not have phones??"[1] but on a way larger scale. At least where i live i am able to use the bare minimum of phones, even working with tech. The friction is inc…

This is good I think because lack of verifications anywhere is good. So at least desktops will be free of it.

Re: EU age verification app not planning desktop support

#203
post #184
post #122

Here's my crack at a good-enough solution for the U.S. It doesn't have a ton of granularity - but the concept is shovel ready now, dirt cheap, and privacy preserving. Video Demo: https://www.youtube.com/watch?v=MmcUJ5u65Q0 Actual Demo: https://app.hornpub.click How it works: 1) Go to app.horpub.click 2) Create an ephemeral passkey 3) Extract its public-key and id (this binds the credential you're creating to your dev…

What happens if some party is able to get logs of the bank's age attestation signings and of hornpub.click's steps #2 and #6? It appears this would present some risk of matching up hornpub.click accounts with real IDs. This is called "linkability" and ideally should be avoided so anonymous age verification can be safe.

Banks and most sites requiring age verification are _littered_ with tracking software that does _literally_ this.

Further, if you put on an adblocker and I get access to the logs at ironbank and hornpub; I could just query them for your IP address.

Collusion to this degree is possible, but doesn't seem worth worrying about if the aforementioned attack vectors still exist. My $0.02.

Re: EU age verification app not planning desktop support

#204
post #6

Earlier quoted context omitted.

> oes that mean we will see a return of the 'desktop applications'...? No. It's still required by law, which means that your desktop application will require some interaction with your smartphone.

The wallet app can be started using a QR code. You can then finish the verification on your phone and continue on the desktop website/app/whatever.

This is plain stupid. Countries (e.g. where I live) already have systems like SPID or CIE that can authenticate users using a multitude of factors, for example I can authenticate myself with a QR and a phone, or I can not even have a phone at all and have a 20 euros NFC reader connected to the PC and can authenticate using my digital document and a PIN.

I see this as a huge stepback to be fair.

Re: EU age verification app not planning desktop support

#205
post #202

> At present the project is focused on mobile platforms, specifically Android and iOS, as they cover the vast majority of users and real-world use cases. (..) Desktop support is not currently within the project's scope. This is the equivalent of a "Do you guys not have phones??"[1] but on a way larger scale. At least where i live i am able to use the bare minimum of phones, even working with tech. The friction is inc…

This is good I think because lack of verifications anywhere is good. So at least desktops will be free of it.

Worse: You just won't be able to use websites on desktop unless you pull out your phone and verify.

Re: EU age verification app not planning desktop support

#206
post #195
post #181

Earlier quoted context omitted.

Chase.com currently is using: mPulse Google Marketing Platform Meta LinkedIn Ads Trade Desk Aggregate Knowledge (Trans Union) Adobe Audience Manger Can you elaborate on how the risk of ironbank and hornpub colluding by de-anonymizing you via rainbow tables or IP forensics is substantially greater than Chase and PornHub using - Google Marketing?

It isn't, but due to bureaucracy, when designing a solution, it's that solution that has to be "secure" without really considering that the current outside situation is already insecure.. Anyway I'm not advocating for this solution, just addressing the question directly.

Thanks for the feedback.

I don't see this as the end all ultimate solution for age verification. I see it more as a tourniquet; imperfect - but better than bleeding to death.

Re: EU age verification app not planning desktop support

#207
post #185

Earlier quoted context omitted.

Of course in the EU - pretty much all Baltic and Nordic countries support id cards connected via usb

Nope, Sweden requires Mobile BankID on iOS or Android for example.

BankID has a desktop version, and no site which requires Mobile BankID would not allow you to also use the desktop version.

Re: EU age verification app not planning desktop support

#208
post #185
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Of course in the EU - pretty much all Baltic and Nordic countries support id cards connected via usb

Well not in Germany. Some banks accept their branded authenticators, some of them don't.

ING in Germany forces you to either have a single Google approved smartphone or a single authenticator, not both.

DKB requires a paid Girocard to use the authenticator or a Google approved smartphone.

N26 requires a single phone but they are a bit lenient. However they have way too many incidents reported where they closed people's accounts without a reason.

The traditional banks have high fees. One pays upwards 10 - 15 Euros a month for Sparkasse or Commerzbank for a simple checking account. Using Sparkasse means you cannot deposit money outside county (yes county and country) borders. Many traditional banks have high fees for withdrawing outside the network.

So one is forced to choose between modern banks with better online experience that's tied to Google and Apple or a traditional bank with oftentimes awful online experience and high fees.

Re: EU age verification app not planning desktop support

#209
post #189
post #156

Earlier quoted context omitted.

If you read the guidelines they actually want to implement a double-blind approach with ZKPs, which imo is significantly better than a challenge-response pub key system in term of privacy. If you're not familiar this would mean the verifier doesn't learns anything except a statement about attributes (age, license, etc); and the EU doesn't learn what attributes have been tried to verify or by who.

Not asking to troll or be a jerk. Promise. What would need to happen in the United States to implement a reliable ZKP age verification system - and how long would it take to roll it out? Asking because it feels like the Titanic has sunk, and we're eschewing a floating door because the coast guard has regulation conformant life rafts that would work better.

> United States to implement a reliable ZKP age verification system (my emphesis)

Realistically at least 3-4 years, assuming they want to keep the same goals as eIDAS. I think the (software) implementation will be the least costly part, time-wise; but it takes a long time before everyone adopts a new social system. Especially in the US where there has been no precedent for digital identification. Even with full control of your own ID & and solid implementation details, there will be push-back just for suggesting that people/companies should adopt it.

Re: EU age verification app not planning desktop support

#210
post #164

I've posted this as a response but I'll post it again since it seems like a lot of people are confused about the project: This project is not THE digital wallet, it is an early prototype of the wallet (which can be criticized for what it is, but the issue is somewhat orthogonal). The actual infrastructure is not based on attenstation, if you read the guidelines (or the readme) they actually want to implement a double…

> a lot of people are confused about the project

This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard cryptography that allows issuers (member state governments) to collude with any verifier (a website requiring age verification) to de-anonymize users. The solution is linkable because both the issuer and the verifier see the same identifiers (the SD-JWT and its signature).

The project is supposed to prove that age verification is viable so that the Commission can use it as a success story, while it completely disregards privacy by design principles in its implementation. That the project intends to perhaps at some point implement privacy enhancing technologies doesn't make it any better. Nothing is more permanent than a temporary solution.

It will also be trivial to circumvent [1], potentially leading to a cycle of obfuscation and weakening of privacy features that are present in the current issuer linkable design.

[1] https://news.ycombinator.com/item?id=44458323

Post reply on HN