Live data from Hacker News

EU age verification app hacked, 2 minute How to posted

xcancel.com

31–33 of 33 posts

Re: EU age verification app hacked, 2 minute How to posted

#31

Earlier quoted context omitted.

Yeah I don’t like how the discussion is shifting to implementation details, instead of debating whether any of this is good or necessary

IMO the implementation is crucial. If everything is locally on the device and I can confirm digitally that I'm older than 18 BUT NOTHING ELSE is leaked, like the German eID supports (I think). Why/how would this be a bad thing?

Because that's debating the mechanics of it rather than the need or the ethics. Nobody gives a shit about the mechanics because if there's a debate about the mechanics that means the discussions about the need and the ethics have already happened. Yet those discussions are in fact still going with few in favour of the ethics or need for these systems. The mechanics are the final step after everything else has been settled.

Re: EU age verification app hacked, 2 minute How to posted

#32
post #18

Earlier quoted context omitted.

Makes no difference in the fundamental dislike i have for the concept

Do you also dislike the concept of requiring to be a certain age to say enter a strip club or a sex club? If not, what is the difference between those controls and having to be a certain age to enter porn sites? Genuinely curious. To me, the primary objection to the online controls has been the implementations. The EU implementation will be[1] even better than the strip club, where the bouncer sees your ID and can re…

> Do you also dislike the concept of requiring to be a certain age to say enter a strip club or a sex club?

You can't compare someone checking your document before entering a strip club (or even a pub, or asking for alcoholic drinks) vs a computer system getting and logging an attestation and verifying it against a government database (or third party) where the Govt knows who the credential belongs to, and who's checking it. Along with my government "compelling me" to run software (even if it's open source itself) that requires me to have a binding contract with a foreign third-party company known for privacy violations, and running their proprietary software stack on my device for said government software to work, so I can participate in most parts of the digital society.

Of course the existing "identity verification" done by scanning yourself and your ID document (passport, national ID or driving licence) is not acceptable, unless counted exceptions where said documentation is needed (banking and others, because of KYC/AML)

Post reply on HN