Live data from Hacker News

Stop Killing the Internet: No Digital ID and No Age Verification

citizens-initiative.europa.eu

281–290 of 313 posts

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#281

The physical world has age checks when kids attempt to enter a premises with dangerous or unsuitable content - eg bars, casinos, strip joints. These seem largely accepted as a good thing. Why do so many seem to feel that the same protections are so outrageous when applied in the virtual world? Honest question, I can see both sides.

Those are false equivalences.

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#282
post #3

Even for a "Citizens' Initiative", this stuff is remarkably tone-deaf. "No Digital ID" ignores the very-real need for people to prove their identity to government(-ish) entities online, and to do so in a reliable, cheap and convenient way. Sure, you do not want that ID to become mandatory for publishing or existing on the Internet in general, but that's a separate discussion: demand sufficient protection for anonymou…

They don’t seem to oppose any of that if you read the intro > We call on the European Commission to propose legislation ensuring that digital identity and age-assurance systems used to access online services in the Union remain voluntary, privacy-preserving and non-discriminatory. Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate an…

Right before that, they explicitly demand that age verification be 100% optional. But I wish they used stronger anti age verification language rather than trying to pay lip service to the assholes attempting to violate privacy.

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#283

Earlier quoted context omitted.

> Having a digital ID does not obviate that (in principle), thanks to zero-knowledge schemes. Yes it does, because zero-knowledge schemes take it as an assumption that all of the people who are supposed to have credentials can be trusted not to share them with people who aren't, since you're proposing a system that provides no means for that to be detected. And this context doesn't allow that assumption. With a norma…

> Yes it does, because zero-knowledge schemes take it as an assumption that all of the people who are supposed to have credentials can be trusted not to share them with people who aren't No, ZK schemes have absolutely nothing to do with sybil resistance. That's a threat modeling concern anyways. If your point is that the entire digital ID plan is nascent because it remains vulnerable to sybil attacks, that it may ver…

> No, ZK schemes have absolutely nothing to do with sybil resistance. That's a threat modeling concern anyways.

Any effective form of sybil resistance itself compromises the privacy that ZK proofs allegedly provide.

Example: You create an account which is then unintentionally linked to your identity in some way, or someone doxxes you. That account is now irrevocably compromised and you need to create a new one, but any effective anti-sybil mechanism prevents you from doing so.

Example: Services use "sign in with Google" or similar to link your activity across services. To prevent this you need a separate Google account for each service, the exact thing any effective anti-sybil mechanism would prevent.

Example: A journalist is doing a series on some company's shady practices. After the first installment, the company uses the published description of the account activity required in order to write the story to identify the small subset of accounts that could belong to the journalist and then bans them or makes their accounts behave differently than ordinary accounts to prevent them from investigating further. An anti-sybil mechanism prevents the journalist from creating a new account not in the identified subset.

Example: A new company wants to create a search engine. Shady websites want to present different content to the search index than they do to users who visit. To detect this the company needs its systems to sometimes request content in a way the site can't distinguish from an ordinary user, to make sure it matches what will go on the search results page. Provide the scammers with an anti-sybil mechanism and once they identify which clients are validating their responses, they give the identified clients the same responses as they give the indexing bot, the search engine can't create new unidentified clients (even while attackers can via identity theft) and you get more scams in the search results page.

Example: A researcher is trying to determine if a service is using redlining, i.e. discriminating on the basis of location. To do this they need to create separate uncorrelated accounts that differ only in their address. An anti-sybil mechanism prevents this.

Example: There is a service the use of which intrinsically reveals some data point about you, e.g. narrows you down from one in 8 billion to one in a billion, each time you use it. Use it twice and it's one in 125 million, then one in 16 million and so on. If your current use isn't correlated with your past use then this is fine. If it is, which is the thing anti-sybil measures require, then repeated use of the service forces you to become uniquely identified.

That's the motte and bailey of zero-knowledge proofs. You present something that would protect privacy as long as it isn't combined with something else that would compromise it, but when it is then the proposed system doesn't actually protect privacy, and if it isn't then it serves no access restricting function and makes the system ineffective and pointless.

> What you describe is (or at least should be) a non-goal for any scheme in this context, because it is fundamentally unsolveable.

That's the point. Identifying someone without identifying them is fundamentally unsolvable. Zero-knowledge proofs cannot make the impossible happen, there is no cryptography that can give you that. But that is the claimed goal of the system -- to prove that someone has characteristic X without having any other information about them.

When you have no other information about them, you cannot establish that they are the person with characteristic X. Anyone can let anyone else use their ID. When you do, the use of zero-knowledge proofs does nothing to prevent the use of that other information to identify them.

> This is (loaded) political speculation, not an argument.

Reasonable political predictions are a valid form of argument. Authoritarians using mass surveillance for oppression and worse has an enormous amount of precedent and the consequences are orders of magnitude more severe than any possible advantages of any form of digital ID.

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#284
post #81

We can talk, talk, and governments will still move forward. Or we can build an alternative that shows it's possible to get age verification while maintaining privacy. There is a real way out of it -- the governments can have their cake and eat it too. I published several academic papers to prove it, and I'm open to building and deploying it. Would anyone want to work on this together: https://magarshak.com/papers.htm…

Personally I think we should build something that makes verification unfeasible instead of building something slightly less worse.

How would it be unfeasible to check someone’s age if it’s feasible now with a driver’s license?

The technogy exists — it is called deepfakes LMAO

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#285

Earlier quoted context omitted.

> it's only legal to have alcohol delivered by the Pennsylvania Liquor Control Board. It is not legal to order directly from producers. You are full of shit. Opinion safely discarded. https://www.pa.gov/agencies/lcb/shop-wine-spirits/direct-win... >The laws do indeed vary by state. I am not disputing that. I am disputing that "most US states, they require the delivery driver to recheck the ID in person" (the original…

While I admit I was wrong, I can say that I didn't actually express any opinion, so there was nothing for you to discard. I do appreciate the rude reply though, thank you for making the environment here so pleasant.

[deleted]

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#286
post #217

Earlier quoted context omitted.

> giving them more power doesn't look like a slippery slope straight to dystopia. Are you seriously saying that with a straight face while (apparently) living in Germany of all places? May I suggest picking up a history book or two?

Believe me, German history education is very thorough in making sure people know that the Nazis weren't some kind of slippery slope situation where people didn't know what they were planning to do. The Nazis were open in their idea that Germany could have won WWI if it hadn't been for those damn lefties and their revolution. They were open about their desire to crush those lefties. They were open about their hatred f…

It was over a decade after the end of the war before the average German person realised the Nazis were the bad guys.

Germany is also involving itself in another war right now where it thinks it is a good guy.

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#287

Earlier quoted context omitted.

> I think the toxic culture of the internet has happened in part because anonymity leads to lack of accountability. It is trivial to demonstrate that this is incorrect (despite sounding plausible). There's plenty of incredibly toxic behavior to be found all over facebook. Among other considerations it's worth noting that most of the usual social feedback mechanisms are missing from typical online interactions. > The…

> There's plenty of incredibly toxic behavior to be found all over facebook. But is it comparable to the amount of toxic behavior on 4chan?

My dad posts daily on Facebook about how much he hates Muslims.

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#288
post #52

Stop letting regular people know they are engaging with bots Only massive data gatherers should be able to track and know everything about people

Wanna be rich? Make a social media company that somehow only allows real people to post. You crack that one, fame and fortune await you...

W Social, the WEF honeypot?

Re: Stop Killing the Internet: No Digital ID and No Age Verification

#290
post #126

How are we on the tech and protocols side of having a truly distributed worldwide mesh-net? i.e. drone swarms replacing ISPs?

It's been working for decades. But nobody uses it except child pornographers. Freenet.

Freenet has been renamed to Hyphanet and then Locutus has been renamed to Freenet.
Post reply on HN