Live data from Hacker News

EU age verification app not planning desktop support

github.com

241–250 of 437 posts

Re: EU age verification app not planning desktop support

#241
post #236

Earlier quoted context omitted.

While everyone took the opportunity to reply to you with "Not in my bank/country/to-my-awareness" This is what's happening in Portugal: https://old.reddit.com/r/portugal/comments/1msc886/obriga%C3... Effectively, if the client doesn't download the App, they will never be able to log into the homebanking website again. The bank enforced this and now if you login normally it will redirect to a page where you can downlo…

Can you expand on: "It has interesting permissions as well ..." ? I assume a banking app needs (temporary) permission to use the camera for check photos or things of that nature ... and possibly (temporary) use of location data. I would be alarmed if it requested microphone or access to either contacts or photo storage ...

I updated the above comment. Cheers.

Re: EU age verification app not planning desktop support

#242
post #205

Earlier quoted context omitted.

Worse: You just won't be able to use websites on desktop unless you pull out your phone and verify.

But this will at least create a healthy pressure for competing options for users on desktops, likely based on novel secure protocols.

Most of the times the user prioritizes more convenient options over privacy. "Pressure for competing options" will mean that options compete for the most convenient way, not most secure or most private.

Re: EU age verification app not planning desktop support

#243
post #238

Earlier quoted context omitted.

Another recent news about mandated app use: Ryanair now (from November) requires using their app for the boarding pass, no more printouts from the desktop. Also, they refuse to show the QR code for the boarding pass in a mobile browser via the website, you must use their app. https://www.msn.com/en-ie/travel/news/ryanair-s-new-check-in...

What about Google Wallet? Or just a PDF from your email?

To me, that's getting bogged down in details. What matters is the intent and direction. Maybe you will have some workarounds for some time. But just as more and more places go cashless, it will also be paperless and mandatory app-based.

Re: EU age verification app not planning desktop support

#244
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

While everyone took the opportunity to reply to you with "Not in my bank/country/to-my-awareness" This is what's happening in Portugal: https://old.reddit.com/r/portugal/comments/1msc886/obriga%C3... Effectively, if the client doesn't download the App, they will never be able to log into the homebanking website again. The bank enforced this and now if you login normally it will redirect to a page where you can downlo…

You say "The bank"... does this mean Portugal only has one bank? If not, wouldn't this be a good reason so change banks? Maybe to a credit union (bank co-op) if they have those in Portugal as the members generally have much more of a say.

Re: EU age verification app not planning desktop support

#245
post #82
post #3

This is a great example of how this whole requirement hasn't been properly thought out. > Desktop support is not currently within the project's scope. What I would like to take from this is that, by their own definition, desktop apps are out of scope for Age Verification. So does that mean we will see a return of the 'desktop applications' instead of everything being a web service ? One can dream perhaps. Until then…

> Also this will completely disable any new phone OS' being developed. Why would anyone bother when you can't verify your wallet to do anything online. This already the case today, you can't run your bank's app or government eID apps on anything but Google or Apple devices.

> This already the case today, you can't run your bank's app or government eID apps on anything but Google or Apple devices.

Fairphone 6 with e/OS begs to differ. Dutch phone with a French OS. No issues.

Re: EU age verification app not planning desktop support

#246
post #242

Earlier quoted context omitted.

But this will at least create a healthy pressure for competing options for users on desktops, likely based on novel secure protocols.

Most of the times the user prioritizes more convenient options over privacy. "Pressure for competing options" will mean that options compete for the most convenient way, not most secure or most private.

Sure, but the point is that the more convenient less-secure ways are going to be criminalized. Otherwise nobody would use the age verification app in the first place.

Re: EU age verification app not planning desktop support

#247
post #225

Earlier quoted context omitted.

Another recent news about mandated app use: Ryanair now (from November) requires using their app for the boarding pass, no more printouts from the desktop. Also, they refuse to show the QR code for the boarding pass in a mobile browser via the website, you must use their app. https://www.msn.com/en-ie/travel/news/ryanair-s-new-check-in...

Big difference between a private company mandating app use, and a government

Functionally, I'm not sure I agree.

Ex - we already have plenty of cases where the government outsources payment processing to 3rd parties. What happens when that private 3rd party declares it's not accepting payments through anything except a mobile app?

Re: EU age verification app not planning desktop support

#248
post #225

Earlier quoted context omitted.

Big difference between a private company mandating app use, and a government

I disagree. It's a tandem, and corporations and the government are increasingly welded together. Also, I'm not too worried about the airport usecase as we're already being tracked and surveilled and inspected there as much as possible. But it's another step to normalize and mandate phone and app use. The puzzle pieces are falling in place. Soon, AI could screen-capture your phone screen to detect suspicious activity,…

> increasingly welded together

That's an insinuation with some vague truth to it, but not much. Budget airlines are not government departments, and competition between them isn't phony.

"The sky is blue" "I feel that it is increasingly yellow"

Re: EU age verification app not planning desktop support

#249

Earlier quoted context omitted.

I disagree. It's a tandem, and corporations and the government are increasingly welded together. Also, I'm not too worried about the airport usecase as we're already being tracked and surveilled and inspected there as much as possible. But it's another step to normalize and mandate phone and app use. The puzzle pieces are falling in place. Soon, AI could screen-capture your phone screen to detect suspicious activity,…

> increasingly welded together That's an insinuation with some vague truth to it, but not much. Budget airlines are not government departments, and competition between them isn't phony. "The sky is blue" "I feel that it is increasingly yellow"

There's little competition pressure because consumers don't care. I guess the standard theory says that the buck ends there. If people are fine with it, it's fine.

Re: EU age verification app not planning desktop support

#250
post #215

Earlier quoted context omitted.

> This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard ECDSA.. The repository we're commenting on has the following in the spec[0]: "A next version of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP)". So given that the cur…

> So given that the current spec is not in use, this seems incorrect. No, that's not what they mean. They just mean that the spec (and for now only the spec, not the implementation) will be amended with an experimental feature, while the implementation will not (yet). I understand (?) that you are interpreting this as: "we'll later document something that we've already implemented", but this is not the case. That isn…

> Anyone of age can make an anonymous age attribute faucet [1] for anyone to use. That it's not technically a bug doesn't make it any less trivial to circumvent. I wouldn't expect the public or even the Commission to make such a distinction. They'll clamor that the solution is broken and that it must be fixed, and at that point I expect the obfuscation and weakening of privacy features to start.

I can see this argument, but it has a few caveats:

- The 'faucet', providing infinite key material in an open proxy is also very vulnerable

- If the only attribute is age verification then uniqueness is not required; i.e. you can borrow the key of someone you trust and that should be fine.

- The unlinkability is a requirement from the law itself, i.e. the current implementation cannot be executed upon assuming rule of law holds

Post reply on HN