Live data from Hacker News

Yoti age checks share facial photos and device fingerprints with third parties

techxplore.com

31–38 of 38 posts

Re: Yoti age checks share facial photos and device fingerprints with third parties

#32
post #18

If a city hires a cop who openly accepts bribes, it's a problem for city hall. If they tolerate crooked cops, they are rightly painted as being corrupt as well. If a government mandates age verification and tolerates companies like Yoti as enforcers of their law, it's exactly the same thing. If politicians aren't willing to see that new laws are enforced with integrity, then these corrupt politicians are the problem…

Can you explain what is the bribe here?

Company A hires company B to offload the burden to do age checks, company B takes the burden to do it securely and only returns an age result to company A (no personal identifiable information).

Company A here could be any site, they are good at creating content, they should not be processing sensitive data. Company B is the expert, their job is to process personal data, confirm age, destroy data.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#33
post #18

If a city hires a cop who openly accepts bribes, it's a problem for city hall. If they tolerate crooked cops, they are rightly painted as being corrupt as well. If a government mandates age verification and tolerates companies like Yoti as enforcers of their law, it's exactly the same thing. If politicians aren't willing to see that new laws are enforced with integrity, then these corrupt politicians are the problem…

Can you explain what is the bribe here? Company A hires company B to offload the burden to do age checks, company B takes the burden to do it securely and only returns an age result to company A (no personal identifiable information). Company A here could be any site, they are good at creating content, they should not be processing sensitive data. Company B is the expert, their job is to process personal data, confir…

"The research team determined that the process Yoti uses to verify a person's age broadcasts the person's personal information to third- and fourth-party companies."

"When a bartender checks an ID, they quickly verify a customer's date of birth and identity before serving them. Companies like Yoti that employ digital age verification claim their products function the same way, but in a completely private manner."

-------------

Company A is not the problem. They called the cops to do cop things. That's fine. Company B (e.g. Yoti) is the one that's operating like a cop. If Yoti is getting paid by those it shares user data with, that's corruption. If they're not being paid, then it's mere criminal negligence.

If governments are to mandate age verification, then they also need to implement privacy standards for the gatekeepers and enforce them.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#34
Update since submission:

An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements

https://www.yoti.com/blog/open-letter-to-georgia-institute-o...

Re: Yoti age checks share facial photos and device fingerprints with third parties

#35
post #29
post #17

Earlier quoted context omitted.

Governments, regardless of what threat they wield against those they supposedly govern, are limited by the fact that they are organizations run by humans. For now. God forbid we ever reach the point where there are no humans... Anyways, because of that they require humans to ensure enforcement. A major reason why Yoti is able to do what it's doing is because there are no humans enforcing privacy and data protection l…

An admirable principled stance that just doesn’t fucking work in the real world. Government processes and staff have zero interest in such stances. Next time you go through a border control try refusing to be searched or scanned on grounds of privacy and see how that goes for you. Lay the chat about broken social contract and how governments are a threat thick enough and officials may decide it’s better if you’re not…

Dude I'm likely on so many lists already it doesn't even matter. Considering the government of my nation is currently levying new threats against the citizenry just about every day it's not even that much to talk about.

I'm just hoping that enough people can be convinced that systems of governance are not immune ethereal constructs run like videogame logic where you cannot do anything not explicitly written down. Too many people think that enforcement of anything works like a zap from God instead of being a mechanism that needs enforcers to pull it off.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#36
post #33

Earlier quoted context omitted.

Can you explain what is the bribe here? Company A hires company B to offload the burden to do age checks, company B takes the burden to do it securely and only returns an age result to company A (no personal identifiable information). Company A here could be any site, they are good at creating content, they should not be processing sensitive data. Company B is the expert, their job is to process personal data, confir…

"The research team determined that the process Yoti uses to verify a person's age broadcasts the person's personal information to third- and fourth-party companies." "When a bartender checks an ID, they quickly verify a customer's date of birth and identity before serving them. Companies like Yoti that employ digital age verification claim their products function the same way, but in a completely private manner." ---…

You have to read the paper (which in itself is quite speculative), but it never says that Yoti is broadcasting face images or ID document images to third or fourth parties. The paper analysed this Yoti platform that allows Company A to decide which age verification methods it wants to offer to their end users. These methods go from age estimation, ID document check and also old school credit card check.

Now credit card check to confirm someone's age is something that existed since ever, and it can only be done by interacting with a payment provider (which is the claimed third/fourth party in the paper) and I can assure you that no one gets paid by the payment provider so you can check a credit card, actually you have to pay them a fee. So in this case Company A is paying a fee to Company B that is running the age check and Company B has its own costs like paying the payment provider a fee to conduct the credit card check. Company B doesn't get paid by anyone else other than Company A, there is no bribe man.

You can clearly see the bias and political intention behind all of this, see also how they use the word "broadcasting" which has a very specific meaning (broadcasting is the distribution of something to a dispersed public audience) which is not what the paper is claiming, there is no broadcasting, any payment provider requires authenticated private and secure connection.

When it comes to the age estimation method and ID document, the paper does not claim that any of that is shared with third parties, as by tracking the network traffic it can see that it goes directly to Yoti. Yoti itself claims and audits his system to prove that any of the personal data they process never leaves their system and is immediately deleted as soon as the age check is done.

The reality is Company B has nothing to gain by keeping or sharing people's data because all they do is based on Company A trusting them and any risk that destroys that trust is unacceptable.

What this political campaign is doing is trying to cast doubts on that trust with lies. So that people like you go and do the campaign for them.

Yoti is being so heavily attacked because they proved that this can be done following high privacy standards, which annoyed quite a lot of people (think the big porn operators for example, which wouldn't be surprising if they are also donors for those privacy groups). It is all about money. If those privacy groups cared about your privacy they would be talking about Google/Apple that know everything you do, anywhere you go, any website or app you use, they even have your biometrics (they say on your phone sure). But as US companies they are obliged to share any data with the US gov if requested and can't tell that to anyone if they ever got that request.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#37

Update since submission: An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements https://www.yoti.com/blog/open-letter-to-georgia-institute-o...

The fact this letter takes aim at something the paper doesn't say is pretty damning. The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties, including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with.

Yoti's letter then gets angry that "face" data is not passed to third parties. That is not what is alleged.

Not to mention the repeated veiled threats about how they "could" sue academics investigating their systems.

It is absolutely incredibly sus as a letter.

Re: Yoti age checks share facial photos and device fingerprints with third parties

#38

Update since submission: An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements https://www.yoti.com/blog/open-letter-to-georgia-institute-o...

The fact this letter takes aim at something the paper doesn't say is pretty damning. The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties, including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with. Yoti's letter then gets angry that "face" data is not passe…

Hey Mindwipe, 100% agree the paper doesn't say that face data is passed to third parties, but then the techexplore article from those universities DOES. That article is the one that this whole thread started on, strangely you are ignoring that.

What's pretty damning is that you make it appear like you know the paper but you claim things that the paper doesn't claim. In the exact same style of those who wrote the article, interesting.

You claim that "The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties"

That is FALSE, the paper doesn't say that, it actually says that the high entropy metadata is sent to Yoti servers, actually encrypted with client side keys on top of TLS which makes it impossible for any third party to even read it.

Reporting here extract from the paper: --- Once the user’s face is properly aligned, the SCM collects and processes a significant amount of data that is sent to Yoti’s servers. In particular, it collects the photo captured from the user’s camera and telemetry, including significant high-entropy browser and device metadata (see Table 2). It also includes data about the camera’s properties, the FPS of the camera stream, and metrics about download and processing times.

The SCM uses some cryptography, which we briefly describe here before returning to its implications in Section 5.5.3. If the image encryption setting is enabled (as it is by default), the SCM encrypts the captured image using AES-GCM with a key and initialization vector (IV) derived in the browser. Similarly, the telemetry and metadata collected is also encrypted under AES-GCM in the browser. ---

Then you claim "including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with."

Which perfectly highlights the issue, as it seems like you might have gotten that from the Abstract section of the paper.

The great thing is that the paper itself disproves all of that when you read all the details. And anyone can find out that the key section where there is actual sharing of data with third parties (not the visiting site) is when the credit card check method is used for example. Which is pretty inevitable, to do a credit card check you need to use a payment provider which will have to process the data necessary to do that.

Post reply on HN