Live data from Hacker News

EU age verification app not planning desktop support

github.com

391–400 of 437 posts

Re: EU age verification app not planning desktop support

#391
post #296

Earlier quoted context omitted.

No, it's a cost cutting measure. App-only reduces support and development costs with whoever they're outsourcing this too. There's a line item which basically said "mobile web" and they wanted it gone to save some number of dollars per year.

I don’t often log in to HN to comment, but when I do it’s usually when I see this type of comment. You can always spot them by the first word being “No” or “False” followed by a confidently asserted yet hilariously incorrect statement. I suggest reading this [0] and approaching these discussions with more humility in the future. As you yourself stated, you’re an SRE, not a security expert, yet this forum is full of t…

Wow! The linked article is downright terrifying. It convinced me that spying is the real purpose of forcing apps on users. How do we look in terms of regulations on this issue? I assume the EU data act covers part of that, right? What do we have for the rest of the world?

Re: EU age verification app not planning desktop support

#392

Tin foil hat time: this is why Google is pushing to kill app sideloading. Mobile phones are the only platform at the moment that can reasonably be used to enforce mandatory software installs and remote attestation. Removing sideloading can down the road leading to Google (or Apple for IOS) forcing all app store provided apps/browsers to support government authentication APIs like this.

Google is gung-ho on embracing every kind of identification law because it aligns with their business model. They sell ads therefore it is important that humans are authenticated. Other social media companies like X have similar incentives.

It's general hard to have discourse online without some good authentication as bots dominate everything. That's why normal people use mostly facebook groups. This needs some solution but gov ID isn't it, unless it's some cryptographic thing that is passed to other services that link data with their own salt or something like that.

Having said that I like how in PL we have very nice auth to all government services that finally works well (it's like 5th implementation of this system). It makes it very easy to use gov services and before had to login with bank accounts or create some crappy accounts. Now it just works with faceID and done.

You can also login to 3rd parties as well. For example I was able to get my medical health results info from commercial provider by sharing basic info from this auth app without creating account or anything (they get access to Gov ID).

Re: EU age verification app not planning desktop support

#393

Earlier quoted context omitted.

Google is gung-ho on embracing every kind of identification law because it aligns with their business model. They sell ads therefore it is important that humans are authenticated. Other social media companies like X have similar incentives.

It's general hard to have discourse online without some good authentication as bots dominate everything. That's why normal people use mostly facebook groups. This needs some solution but gov ID isn't it, unless it's some cryptographic thing that is passed to other services that link data with their own salt or something like that. Having said that I like how in PL we have very nice auth to all government services tha…

If there was something like that guarantees pseudonymous ID that can't be reversed via rainbow tables like stuff that could be useful as general login ID.

I would like to have ability to choose if I use new one for this provider or one that can be linked with other services. Kinda like with apple anonymising emails. Are there any efforts in this directions?

Re: EU age verification app not planning desktop support

#394
post #297

When the UK age verification legislation was being debated I recall people saying "don't worry about unintended consequences, it's not like you'll be have to show your ID to random websites! Someone will show up with a reasonable methodology. You'll be able to e.g. show your ID at a shop and get an anonymous token.". And plenty of people, including myself, thought "this is so dystopian it couldn't possibly happen". I…

I would be curious what it's like in the UK. It would probably do well as an HN submission if you're up for writing a blog post about it. All I know is that they passed some legislation that requires people to authenticate for anything that could possibly show nudity or something, including Wikipedia, and that VPN apps were going wild. I don't know what it's actually like in daily life, how one does authenticate to W…

Personally I haven't noticed anything with Wikipedia, or Reddit (only ever used when searching for opinions through Google with "Reddit" on the search query).

If you want to watch porn or view anything NSFW with websites that complied, I suppose you just start up NordVPN and select Chicago or something like that. Brits who watch porn are probably just watching more American themed porn now.

Otherwise, (some of) these websites are supposed to show you a digital verification screen with third party gateways. Usually using an ID card. I'd guess most people just installed VPNs.

Re: EU age verification app not planning desktop support

#395
post #296

Earlier quoted context omitted.

No, it's a cost cutting measure. App-only reduces support and development costs with whoever they're outsourcing this too. There's a line item which basically said "mobile web" and they wanted it gone to save some number of dollars per year.

Ther's a line between "we don't support this platform" and actively making it hostile to try and use a platform. It may have even taken extra development time to make sure they can reject showing the QR code on a webpage, if their app is just serving that same web page.

If corporate no longer wants to support mobile web, then it means I don't have budget to host it. It means developers can't put time against fixing it, QA aren't tasked to test it before releases, and support staff are not being trained in supporting it. The last one is pretty key because it's a huge metric for cost center: how many support calls is a thing generating? And if the thing is not supposed to exist anymore, then I would have to answer questions like "why is it still accessible?"

Internal job tracking metrics would have to answer why any time is going to running this thing, and god help us if there's a security breach via this endpoint we were supposed to have eliminated N time ago.

An unsupported internal API is one thing - and they're generally a huge timesink anyway. An unsupported external user interface is a cost center which I can't justify, and impacts numerous other parts of the business.

Re: EU age verification app not planning desktop support

#396

Earlier quoted context omitted.

BankID has a desktop version, and no site which requires Mobile BankID would not allow you to also use the desktop version.

But it doesn't support Linux.

It used to, it could quickly get back support if there was a reason to.

Re: EU age verification app not planning desktop support

#397

Earlier quoted context omitted.

Well, looking around I see more people using smartphones for anything and even not having a PC…

The vast majority of those people are never going to know the freedom and power afforded by using a general purpose computer you actually control. The "war on general purpose computing" need only be the waiting-out for those of us who remember actually owning a computer to die.

I secretly believe that the PC is simply so unbelievably powerful that its impossible to kill

Re: EU age verification app not planning desktop support

#398
post #123

Earlier quoted context omitted.

you could pretty much replace the statement with "General purpose computing considered harmful"

or user 'having free will is problematic and unsafe' if we want to go even deeper :(

What is the location of your free will in your body? Is it in brain or in quantum particles, or anywhere else?

Re: EU age verification app not planning desktop support

#399

A lot of people outraged by this but ultimately this is good news - the more flagrant & public the technical incompetence of the people putting together these idiotic systems, the easier mass push back will be to foment.

Mass push back from whom?

Most people don't care about this. They spend hours per day on a surveillance device, willingly contributing their data, personal information and media to monopolistic companies, including putting it into the public online sphere for the world to see. Many people are genuinely convinced this is about the safety of kids, even though the same workarounds slightly competent users know how to implement (VPNs) are the exact same tool the supposed evil-doers know how to use.

Re: EU age verification app not planning desktop support

#400
post #304
post #218

Earlier quoted context omitted.

My German bank started to require an Android or IOS smartphone [0]. No dedicated HW, no desktop. I actually dumped my well working Xiaomi Phone because it was either security or banking. [0] https://www.1822direkt.de/service/fragen-und-antworten/detai...

I actually considered switching to 1822direkt last year. No more!

They used to be ahead of the bunch 20 years ago. They sent out PGP encrypted transaction statements if you wanted. Then they degraded. I think of switching to a normal Sparkasse, they typically even can do account creation with EID l, have Wero and allow 2FA Hardware.

Absurd thing is that 1822 claims to make things much more secure but their 2FA reset with a single phone PIN is a joke.

Post reply on HN