Live data from Hacker News

EU age verification app not planning desktop support

github.com

301–310 of 437 posts

Re: EU age verification app not planning desktop support

#301
post #129

Earlier quoted context omitted.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

Which banks? Which country? How do they check and enforce iPhone / Google wrt. 2FA? Are you referring to TOTP as 2FA?

All banks are required to have "safe" 2FA in the EU by EU regulation. SMS is banned.

Most banks in Germany, Austria and Portugal default to Play Store or App Store apps with OS integrity checks. It seems like the Nordic countries have it a bit better with the ID reader apps. There are sometimes alternatives and some of them require paid subscription.

The apps they require are proprietary. They are not generic TOTP generators. Some of them require biometric approval. Some just logging in and approving a notification. I have seen some generate a form of non-standard TOTP. Otherwise I wouldn't complain about being locked into Google or Apple ecosystems. They are Play Store or App Store apps that require attestation from the libraries / systems provided Google or Apple like SafetyNet or Play Integrity. Some require strong hardware attestation. If the OS is modified, those checks do not pass. You cannot use any FOSS system without crazy hacks. If the phone is stolen, you have to go through manual reonboarding. It sucks when you're out of the country.

Re: EU age verification app not planning desktop support

#302
post #14

so a smartphone is required by law? that's fucked up

No! Only required if you want to participate in society. And what gets me is that it's not just 'you need a phone', it's 'you need a Google or Apple account'.

You don't only need the account, you need a phone that is locked down with hardware components and cryptographic keys that attest it hasn't been modified "unauthorizedly". Where the authority is not the device "owner" but Google, Apple, and the manufacturer

The account would be easy enough with fake data and a 10€ prepaid one-time-use phone number. Finding an exploit in Android such that you can turn off Google's tracking but not trigger their "you modified your device" scans (that are to be tied to your government identity verification continuing to work) is a game I'm not looking forward to playing.

Re: EU age verification app not planning desktop support

#303
post #296

Earlier quoted context omitted.

A BIG reason these companies like Ryanair want you to use their app its that it's much easier to collect data about you than through a website :(

No, it's a cost cutting measure. App-only reduces support and development costs with whoever they're outsourcing this too. There's a line item which basically said "mobile web" and they wanted it gone to save some number of dollars per year.

No, sending a pdf by email is no extra cost. They already have an email output interface for tickets and recipts and confirmations.

It's all about better tracking. I'm not quite sure what additional info they get exactly, but tons and tons of mobile websites (that work and don't get deleted) are close to unusable due to a barrage of popups telling you to use the app (e.g. Reddit and other socials).

Also there is no indication they will stop the mobile web version. Already today the mobile web version is there but it explicitly refuses to show the boarding pass QR code: https://i.redd.it/lj3wdnfp9mq91.jpg

Re: EU age verification app not planning desktop support

#304
post #218
post #208

Earlier quoted context omitted.

Well not in Germany. Some banks accept their branded authenticators, some of them don't. ING in Germany forces you to either have a single Google approved smartphone or a single authenticator, not both. DKB requires a paid Girocard to use the authenticator or a Google approved smartphone. N26 requires a single phone but they are a bit lenient. However they have way too many incidents reported where they closed people…

My German bank started to require an Android or IOS smartphone [0]. No dedicated HW, no desktop. I actually dumped my well working Xiaomi Phone because it was either security or banking. [0] https://www.1822direkt.de/service/fragen-und-antworten/detai...

I actually considered switching to 1822direkt last year. No more!

Re: EU age verification app not planning desktop support

#305
post #296

Earlier quoted context omitted.

No, it's a cost cutting measure. App-only reduces support and development costs with whoever they're outsourcing this too. There's a line item which basically said "mobile web" and they wanted it gone to save some number of dollars per year.

No, sending a pdf by email is no extra cost. They already have an email output interface for tickets and recipts and confirmations. It's all about better tracking. I'm not quite sure what additional info they get exactly, but tons and tons of mobile websites (that work and don't get deleted) are close to unusable due to a barrage of popups telling you to use the app (e.g. Reddit and other socials). Also there is no i…

As an SRE I can assure you that "sending a PDF by email" is far from free to support, and anything email is pretty much top of the list to eliminate.

Re: EU age verification app not planning desktop support

#306
post #298

Earlier quoted context omitted.

There's little competition pressure because consumers don't care. I guess the standard theory says that the buck ends there. If people are fine with it, it's fine.

You are arguing there's little competition pressure between budget airlines, a business with notoriously razor thin margins which people shop almost exclusively on price to the exclusion of all other parameters? This isn't a serious argument.

Only price pressure. No measurable number of consumers will choose a different airline due to their boarding pass app policy.

Re: EU age verification app not planning desktop support

#307
post #17

Lets pretend the EU would mandate Desktop Support, we all know it will be only applied to Windows and Apple. Maybe for Linux, BSD it will never be applied. In anycase we all know ways of bypassing this age verification will be found, probably by the kids themselves. But all this will do is enable US big tech, killing the very EU based companies the EU has been crying about for years. Meta, Twitter, Google and M/S cou…

Kids will bypass any verification by secretly using an adult ID or just straight away asking them to do it.

Hell the crazy things I used to do to connect to the internet after my mother went to sleep. She didn't wanted me using the internet because of phone charges so I secretly got into the roof to strip the phone wire bare and connect my own hidden cable that I would unroll and route it to my room to connect to my modem at night. YES part of it was to watch porn and download mp3s and roms. No I wasn't of legal age. Did my life got ruined by this? Well I'm an IT engineer now so arrive at your own conclusion.

I think this current hysteric moral panic is definitely being pushed by a lobby of a nascent AI industry that wants to create a problem for their surveillance tech solution.

Re: EU age verification app not planning desktop support

#308

I looked into the Swiss version of this, which is documented here: https://swiyu-admin-ch.github.io/ They faced the same question. Here is their answer: https://github.com/orgs/swiyu-admin-ch/discussions/20 The tldr is that they have a legal requirement to bind "verifiable credential shares" with the same human who got the e-ID originally, up to the current best practical technology. On Android, they judge that to be…

> The tldr is that they have a legal requirement to bind "verifiable credential shares" with the same human who got the e-ID

Glancing at the thread, I don't see that conclusion. User 'sideeffect42' cites some laws and says

>> As I read this it nowhere says that the e-ID has to be bound to a device. It only speaks about binding it to its owner which (IANAL) could be implemented by password protection (like KeePass) as well, since only the owner knows the password.

Nobody seems to have replied to that

Alternatively, the software could just scan your ID card's chip when you need it, or whatever it is that it does for first-time-use verification anyway. It needs not require your phone is locked down, locking you out of any control over tracking, installed apps, or reading the phone's storage and network traffic to merely see what it tracks about you. The phone can simply act as an NFC reader so that your ID can sign a challenge with an "over 18" flag included within the signed data

And that's if you want ubiquitous age verification in the first place. I find that u/raincole made a good point here that outlandish implementations have successfully shifted the discussion away from the aspect of whether ID-based checks must be widely performed: https://news.ycombinator.com/item?id=45361883

> so I urge [to vote a certain way], if you're a Swiss citizen

Is this post genuinely trying to add something to the thread, or a way to promote your agenda?

Re: EU age verification app not planning desktop support

#309
post #287
post #38

Tangentially, I would love to be able to see the age of everyone on the internet. IRL this gives us so much context when having an interaction.

I can't find which document it was specifically, but I seem to remember that the hackers' ethos always been that it doesn't matter who you are, what your title is or skin looks like, but that your arguments are to be valued by its merit rather than by who says it. Age seems like another one of these properties you are stuck with

I agree with that, I'm not arguing for discrediting arguments by age and ask for authority of the elders or something of that sort. Age provides context, it's helpful with facilitating the conversation in a healthier manner. Just the other day I was having an intense argument with someone on reddit, at some point it occurred to me that they don't understand because they are too young(checked the profile, definitely some kid trying to have an opinion on grown up stuff) and my words don't ring a thing in their head. Instead of being angry for them being too stupid to understand, I decided that they are not stupid or bad people but just too young. I was at that age some time ago and I knew how it feels, so left them alone. They will understand when they understand.

This is because words actually don't carry much meaning, they invoke something that the other side understands already. For example, it's very hard to have a conversation about some aspects of a relation of 40 y/o people if the other party is in their 20s. You need to relate with something of their age and build it up and even then its likely they will understand it completely the wrong way. Over the years people evolve, they go over stuff and when you meet someone who hasn't been through the process you need to be aware of that otherwise you will mistake them for stupid(because, not everyone who ages ends up going through the transformation the same way. You better know if you are speaking to such a person or a younger person who has the chance).

What I don't understand is, why people assume that everything you know about someone is supposed to be used against them. Why everything needs to be malicious?

Re: EU age verification app not planning desktop support

#310
post #305

Earlier quoted context omitted.

No, sending a pdf by email is no extra cost. They already have an email output interface for tickets and recipts and confirmations. It's all about better tracking. I'm not quite sure what additional info they get exactly, but tons and tons of mobile websites (that work and don't get deleted) are close to unusable due to a barrage of popups telling you to use the app (e.g. Reddit and other socials). Also there is no i…

As an SRE I can assure you that "sending a PDF by email" is far from free to support, and anything email is pretty much top of the list to eliminate.

It doesn't need to be by email. They can simply show it in the mobile website.

But they refuse to do so in order to get all that data which they can sell. In a mobile app it's way harder to run ad blockers and much easier to sneakily collect information on the user. Especially on android which is by far the biggest OS in the countries where Ryanair operates.

Post reply on HN