Live data from Hacker News

EU age verification app not planning desktop support

github.com

221–230 of 437 posts

Re: EU age verification app not planning desktop support

#221
post #3

This is a great example of how this whole requirement hasn't been properly thought out. > Desktop support is not currently within the project's scope. What I would like to take from this is that, by their own definition, desktop apps are out of scope for Age Verification. So does that mean we will see a return of the 'desktop applications' instead of everything being a web service ? One can dream perhaps. Until then…

> What I would like to take from this is that, by their own definition, desktop apps are out of scope for Age Verification. So does that mean we will see a return of the 'desktop applications' instead of everything being a web service ?

I doubt it unless something odd happens like triggering some reaction. They’ve looked at the data and see the majority of society using “phones”, which are really just increasingly small computers that happen to have a feature to also make calls; and they’ve decided that this trap they’re leading us all into can and may even need to stay open and inviting for a while anyways until the older people die off and desktop form factors kind of fall by the wayside, before the trap is even ready to be sprung. In the mean time they’ll just gaslight and lie about what they’re doing, to save and protect the children of course, until the day that you tune around from a distraction and the trap door is shut behind you.

It’s the same MO as always, with the gullible and naive enablers being essentially the worse threat than the actual perpetrators.

Re: EU age verification app not planning desktop support

#222
post #215

Earlier quoted context omitted.

> a lot of people are confused about the project This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard cryptography that allows issuers (member state governments) to collude with any verifier (a website requiring age verification) to de-anonymize users. The solution is linkable because both the issuer and…

> This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard ECDSA.. The repository we're commenting on has the following in the spec[0]: "A next version of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP)". So given that the cur…

> So given that the current spec is not in use, this seems incorrect.

No, that's not what they mean. They just mean that the spec (and for now only the spec, not the implementation) will be amended with an experimental feature, while the implementation will not (yet).

I understand (?) that you are interpreting this as: "we'll later document something that we've already implemented", but this is not the case. That isn't how this project operates, and I'm intimately familiar with the codebase so I'm completely certain they haven't implemented this at all. There is no beginning or even a stub for this feature to land, which is problematic, as an unlinkable signature scheme isn't just a drop-in replacement, but requires careful design. Hence privacy by design.

> If you have a key with the attribute of course you can 'bypass' it, I don't think that's bug.

Anyone of age can make an anonymous age attribute faucet [1] for anyone to use. That it's not technically a bug doesn't make it any less trivial to circumvent. I wouldn't expect the public or even the Commission to make such a distinction. They'll clamor that the solution is broken and that it must be fixed, and at that point I expect the obfuscation and weakening of privacy features to start.

So as we already know that the solution will be trivial to circumvent, it shouldn't be released without at least very clearly and publicly announcing it's limitations. Only if such expectations are correctly set, we have a chance not to end up in a cycle where the open source and privacy story will be abandoned in the name of security.

[1] Because of the linkable signature scheme in principle misuse can be detected by issuers, but this would be in direct contradiction with their privacy claims (namely that the issuer pinky promises not to record any issued credentials or signatures).

Re: EU age verification app not planning desktop support

#223
post #205
post #202

Earlier quoted context omitted.

This is good I think because lack of verifications anywhere is good. So at least desktops will be free of it.

Worse: You just won't be able to use websites on desktop unless you pull out your phone and verify.

But this will at least create a healthy pressure for competing options for users on desktops, likely based on novel secure protocols.

Re: EU age verification app not planning desktop support

#224

> At present the project is focused on mobile platforms, specifically Android and iOS, as they cover the vast majority of users and real-world use cases. (..) Desktop support is not currently within the project's scope. This is the equivalent of a "Do you guys not have phones??"[1] but on a way larger scale. At least where i live i am able to use the bare minimum of phones, even working with tech. The friction is inc…

Another recent news about mandated app use: Ryanair now (from November) requires using their app for the boarding pass, no more printouts from the desktop. Also, they refuse to show the QR code for the boarding pass in a mobile browser via the website, you must use their app.

https://www.msn.com/en-ie/travel/news/ryanair-s-new-check-in...

Re: EU age verification app not planning desktop support

#225

> At present the project is focused on mobile platforms, specifically Android and iOS, as they cover the vast majority of users and real-world use cases. (..) Desktop support is not currently within the project's scope. This is the equivalent of a "Do you guys not have phones??"[1] but on a way larger scale. At least where i live i am able to use the bare minimum of phones, even working with tech. The friction is inc…

Another recent news about mandated app use: Ryanair now (from November) requires using their app for the boarding pass, no more printouts from the desktop. Also, they refuse to show the QR code for the boarding pass in a mobile browser via the website, you must use their app. https://www.msn.com/en-ie/travel/news/ryanair-s-new-check-in...

Big difference between a private company mandating app use, and a government

Re: EU age verification app not planning desktop support

#226
post #67

These EU politicans should stay the fuck out of things they refuse to understand unless they want to see a real darknet take off.

At this point I think they very well do understand. Rocky times are ahead, TPTB know they're at risk if things get bad enough for the average denizen and they want to get in as much leverage against future dissidents as possible.

Re: EU age verification app not planning desktop support

#227

"This makes the web unusable for anyone who wants to browse the web privately." This is not an accident. This is intent. Look at the arrests for social media posts in the UK and Germany.

And Hungary

https://www.euronews.com/my-europe/2020/05/14/hungary-critic...

Re: EU age verification app not planning desktop support

#228
post #225

Earlier quoted context omitted.

Another recent news about mandated app use: Ryanair now (from November) requires using their app for the boarding pass, no more printouts from the desktop. Also, they refuse to show the QR code for the boarding pass in a mobile browser via the website, you must use their app. https://www.msn.com/en-ie/travel/news/ryanair-s-new-check-in...

Big difference between a private company mandating app use, and a government

I disagree. It's a tandem, and corporations and the government are increasingly welded together.

Also, I'm not too worried about the airport usecase as we're already being tracked and surveilled and inspected there as much as possible.

But it's another step to normalize and mandate phone and app use. The puzzle pieces are falling in place. Soon, AI could screen-capture your phone screen to detect suspicious activity, and track every tap you do, also taking pictures with the front-facing camera without you knowing, listening on the mic, etc. etc., connecting it all to your real identity. Because why not? If it's done step by step, nobody will care at all. Maybe that sounds pessimistic, but it looks like the end game and I see no principled political stance against it, nor any insurmountable technical hurdles.

Re: EU age verification app not planning desktop support

#229
post #5

This is hardware attestation in a nutshell: a double edged sword, and a sharp one at that. The biggest issue is that the attestation hardware and the application client is the same device with the same manufacturer, who also happens to have a slight conflict of interest between monetizing customers and preserving any sort of privacy. IMHO the pro-attestation forces are so overwhelming that we should all cherish the m…

My understanding of the "double edged sword" idiom is that the tool has both downsides and upsides. What are the upsides to restricting what I can do with the hardware I paid for?

Re: EU age verification app not planning desktop support

#230

Earlier quoted context omitted.

Sure. But the EU is not just your average bureaucracy. It's an entity that has as one of it's specific goals the following[1]: > combat social exclusion and discrimination [1] https://european-union.europa.eu/principles-countries-histor...

Any large bureaucracy has similarly lofty official goals

I understand we're all old and cynical here, but one of the tenets of discussions on HN would be to take someone's arguments at face value, so I prefer to believe that the EU as an organization actually wants to diminish social exclusion and discrimination. I'm not sure if I'd give the same credit to any other capitalist entity, but the EU does not have the implicit goal of increasing revenue for its shareholders to subvert any of the others stated.
Post reply on HN