Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

211–220 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#211
post #169

Earlier quoted context omitted.

Giving your kid a gateway to every bad thing on the internet is not life as usual. It's incredibly recent, and I don't have shares in SSRI manufacturers, so I don't like it.

Having a smartphone at all also is incredibly recent, so by that logic we shouldn't let anyone have them. Alternately, maybe we can recognize that they haven't been long enough for any specific way of using them to be the long-term universal standard. In the meantime, I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting. I literally don…

> so by that logic we shouldn't let anyone have them

It's pretty normal to treat kids differently to adults in specific areas.

> I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting

This argument goes both ways - currently there are no safety rails for kids, and that is imposed on people who want safety rails.

> That doesn't make it reasonable to have a policy that requires literally the exact people who aren't the ones that are ostensibly supposed to be protected by the system tracked by it

And there are definitely situations where adults' experiences are degraded because a place has to accommodate children. I agree that I hate tracking and so forth, but I wouldn't pretend that children using smartphones isn't a pretty well-understood bad idea either.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#212
post #169

Earlier quoted context omitted.

Having a smartphone at all also is incredibly recent, so by that logic we shouldn't let anyone have them. Alternately, maybe we can recognize that they haven't been long enough for any specific way of using them to be the long-term universal standard. In the meantime, I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting. I literally don…

> so by that logic we shouldn't let anyone have them It's pretty normal to treat kids differently to adults in specific areas. > I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting This argument goes both ways - currently there are no safety rails for kids, and that is imposed on people who want safety rails. > That doesn't make it rea…

> This argument goes both ways - currently there are no safety rails for kids, and that is imposed on people who want safety rails.

No, it's imposed on every adult regardless of if they want safety rails, and in a way that literally only affects the people who aren't actually the ones the rails are ostensibly supposed to be protecting.

> I wouldn't pretend that children using smartphones isn't a pretty well-understood bad idea either.

You literally just said that it's "incredibly recent", and now you're claiming that it's well understood. I'd argue that those things are inherently at odds; we literally don't know what a young child who used a smartphone looks like at 30 years old right now because they haven't been around long enough. On top of all of that, there's literally nothing about invading someone's privacy that's needed to stop a child from using a smartphone: just don't give them the smartphone! That's always been an option, and nothing about this policy that will have any effect on whether parents give their kids access to their smartphones.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#213
post #181

Earlier quoted context omitted.

Let's take an example with a current project of law from Macron (french president): "Some people can't support their health condition, and they should be helped to die". This end of life law is introduced like a care service for people having issue with health with no happy ending at sight. The reality of the vision of Macron (liberale capitalist) is: All his actions are made to kill public health care, and aims to o…

It might help to broaden your perspective a bit and look at multiple sources, before you spread rumours like they are facts. Under Emmanuel Macron, France has been debating a law on “assisted dying” ( aide à mourir ). This is not a general idea that “some people should be helped to die,” but a narrowly defined proposal. The draft would apply only in very specific situations: - Adults (18+) - With a serious and incura…

I know this law would not apply to anyone.

I'm not trying to spread rumours, i said i wasn't english native, sorry if there is a misunderstanding.

Almost 100% of the population that is targeted by this law *should* not need it. When I said "people can't pay [for private paliative healthcare because public healthcare is going to be more and more broken]" I was talking about the people in the criteria of the law, not "all" the people.

I don't have the exact number, but for people under heavy care needs, palliative care, only something like x% (this is the number i cant recall, less says it's a "part") could ask themselves if they should access this end of life because science + our healthcare system cant do much more.

The other part, if they think about end of life is because the health care system failed them. Because in France public palliative healthcare teams are on budget cuts. Those people should have physical and mental healthcare, instead, they have just what the teams can do best as they can cuts after cuts. What happend when you are in paliative care, and there is no team to help your mental health? What could you think about and what does this law allow ?

There is no kind or dignity in Macron's law.

Really, we could save a "part" of that population, but instead priorise to allow them to die, for supposed kindness. True kindness would have been to focus to provide a decent public healthcare system especially in paliative field, for example, right ? (But Macron effort are to destroy the healthcare system and, in my opinion, not a rumour, that it is Orweilien to propose this law in this specific context in France)

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#214
post #212

Earlier quoted context omitted.

> so by that logic we shouldn't let anyone have them It's pretty normal to treat kids differently to adults in specific areas. > I still don't understand why someone with no kids should have their access gated based on what opinions other people have on parenting This argument goes both ways - currently there are no safety rails for kids, and that is imposed on people who want safety rails. > That doesn't make it rea…

> This argument goes both ways - currently there are no safety rails for kids, and that is imposed on people who want safety rails. No, it's imposed on every adult regardless of if they want safety rails, and in a way that literally only affects the people who aren't actually the ones the rails are ostensibly supposed to be protecting. > I wouldn't pretend that children using smartphones isn't a pretty well-understoo…

> No, it's imposed on every adult regardless of if they want safety rails

I don't understand. We're talking about something that hasn't happened yet. The safety rails do not exist, even for those who want them.

> You literally just said that it's "incredibly recent", and now you're claiming that it's well understood

Yes - incredibly recent in the grand scheme of history, but still we have a lot of evidence of the negative aspects of onlineness and phone use over the last 15 years at least. And, as another example, it's far more recent that girls turn 18 and celebrate that on OnlyFans. I would argue that while I haven't waited 30 years to see how they turn out at 50, that it's a bad idea.

> On top of all of that, there's literally nothing about invading someone's privacy that's needed to stop a child from using a smartphone: just don't give them the smartphone! That's always been an option, and nothing about this policy that will have any effect on whether parents give their kids access to their smartphones.

I agree - I think this is a parenting issue, but at least on the left, which the EU tends to, parents should offload their responsibility where possible to the state. But that's my answer to this overall. I'm just arguing specifics.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#215
post #95

Earlier quoted context omitted.

Most countries in the EU already have widely accepted identity proof apps mostly verified by the banks or the government itself. Once verified the identity app gets a certificate which is signed by the authority which issues the identity. We all know how that works as that’s how TLS works as well. The zero proof age check is based on verifiable credentials and the related verifiable presentation. Once you have a wall…

Ah, and the sites (or whatever else) can then verify the key is valid locally? Assuming that is the case, that'd make for a surprisingly nice system, further assuming that the produced credential is not reversible. I'm highly cynical and so I expected it to be a backdoor for surveillance as it feels like most things under the pretext of 'won't anybody think about the children' are.

The site can verify the signature of the presentation document using the public key of the credential issuer, yes. Each presentation is generated on demand to avoid identity tracking (sites could collide to to track presentations otherwise).

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#216
post #203

Earlier quoted context omitted.

> And now it becomes clear that what you want is non-anonymity, rather than age. No. Proving your age anonymously is more than enough to prove you're a human and that is all that is needed.

Apparently you want "approved location", too. Precise age and general location is already sometimes enough to completely identify a person. That alone would make it far easier to, for instance, track people down based on their social media posts. Forced proof of identity is damage, and the Internet should route around it. Every last bit of this should be destroyed, along with the political careers of anyone who suppo…

> Apparently you want "approved location", too.

Yes, country. Generally proved enough by the ID being issued by that country, or a neighbouring one.

> Forced proof of identity is damage, and the Internet should route around it. Every last bit of this should be destroyed, along with the political careers of anyone who supports it.

Have you heard of the dead internet? The internet is already damaged beyond repair by hostile corporate and political interetests. The only way it becomes for humans again is by enforcing verification of humanness in critical parts of it.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#217
post #216

Earlier quoted context omitted.

Apparently you want "approved location", too. Precise age and general location is already sometimes enough to completely identify a person. That alone would make it far easier to, for instance, track people down based on their social media posts. Forced proof of identity is damage, and the Internet should route around it. Every last bit of this should be destroyed, along with the political careers of anyone who suppo…

> Apparently you want "approved location", too. Yes, country. Generally proved enough by the ID being issued by that country, or a neighbouring one. > Forced proof of identity is damage, and the Internet should route around it. Every last bit of this should be destroyed, along with the political careers of anyone who supports it. Have you heard of the dead internet? The internet is already damaged beyond repair by ho…

I am well aware of the problem of election interference. I am also well aware of the problems of forcing everyone involved in a discussion of political topics to be identified. I think we could solve the former without the latter, in a wide variety of ways (e.g. dealing with bots, regulating AI/LLMs, restricting algorithmic content promotion). And you can't have the latter anyway; the cost of forcing people to identify themselves is far too high, and there will always be places to have discussions without doing so, whether you want there to be or not. Again, forced proof of identity is damage, and the Internet will route around it.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#218
post #216

Earlier quoted context omitted.

> Apparently you want "approved location", too. Yes, country. Generally proved enough by the ID being issued by that country, or a neighbouring one. > Forced proof of identity is damage, and the Internet should route around it. Every last bit of this should be destroyed, along with the political careers of anyone who supports it. Have you heard of the dead internet? The internet is already damaged beyond repair by ho…

I am well aware of the problem of election interference. I am also well aware of the problems of forcing everyone involved in a discussion of political topics to be identified. I think we could solve the former without the latter, in a wide variety of ways (e.g. dealing with bots, regulating AI/LLMs, restricting algorithmic content promotion). And you can't have the latter anyway; the cost of forcing people to identi…

> I am well aware of the problem of election interference. I am also well aware of the problems of forcing everyone involved in a discussion of political topics to be identified. I think we could solve the former without the latter

Again, I'm not talking about identifying people individually, but identifying them as real people over 18. With the planned and starting to exist EU infrastructure around this, with double blind proof of age (and thus humanity), we have that and it's still Anonymous.

> and there will always be places to have discussions without doing so, whether you want there to be or not.

That is actually kind of irrelevant, because people discussing in small numbers is not the problem. Malicious actors twisting public discourse is. So all that's needed is strict guardrails around the big public forums (social media).

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#219
post #213

Earlier quoted context omitted.

It might help to broaden your perspective a bit and look at multiple sources, before you spread rumours like they are facts. Under Emmanuel Macron, France has been debating a law on “assisted dying” ( aide à mourir ). This is not a general idea that “some people should be helped to die,” but a narrowly defined proposal. The draft would apply only in very specific situations: - Adults (18+) - With a serious and incura…

I know this law would not apply to anyone. I'm not trying to spread rumours, i said i wasn't english native, sorry if there is a misunderstanding. Almost 100% of the population that is targeted by this law *should* not need it. When I said "people can't pay [for private paliative healthcare because public healthcare is going to be more and more broken]" I was talking about the people in the criteria of the law, not "…

I think you should let someone explain Macron's law to you, because you're clearly unable to understand how it works and why it is being proposed even though I wrote a pretty clear explanation for you.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#220
post #195

Earlier quoted context omitted.

Their security model requires remote attestation. So, open, user-controlled platforms cannot be used. Of course some other future locked-down linux-based OS might be usable.

Remote attestation in theory includes all aosp-compliant attestation implementations (in practice that's GrapheneOS already), but the current project plans and implementation openly reject it.

Only "open" in a twisted sense, and definitely not user-controlled: Remote attestation per definition means to accept only pre-approved operating systems. If anybody builds an implementation, regardless whether it is aosp-compliant or not, this will be excluded, until the App developer or someone in the chain explicitly approves that implementation. That is the whole purpose of that technology. Including GrapheneOS in that pre-approved list just shifts power from Google and the App Developer to GrapheneOS Developers and the App Developer. Nice for GraphenOS, still bad for users and devs of any other OS variant or platform.
Post reply on HN