Live data from Hacker News

I'm reluctant to verify my identity or age for any online services

neilzone.co.uk

391–400 of 645 posts

Re: I'm reluctant to verify my identity or age for any online services

#391

It is likely not a coincidence that so many different countries simultaneously started pushing for age verification. The decline of privacy, the increase in intrusive government surveillance, the increasing restrictions on free speech - this is all part of a very disturbing pattern. Our governments are becoming increasingly authoritarian, and these are the tools they use to keep the populace under control.

> It is likely not a coincidence that so many different countries simultaneously started pushing for age verification.

I thought in many places it was related to the upcoming minimum age for social media. To verify age you need an ID. That's how we make it so most kids can't buy cigarettes, alcohol, thc, etc. You could argue social media shouldn't have a minimum age but that'll be the reality it looks like. How do we do that without ID?

Re: I'm reluctant to verify my identity or age for any online services

#393
post #6

I was sitting in a room the other day with a young adult, we were searching for additional algorithm learning materials. They searched in Google, and accept the cookies. They clicked on a website, and accepted those cookies too. They then started entering their email address to access another service. I was completely taken aback. I'm the sort of person that either rejects the cookies, or will use another site entire…

I've been saying this for years. GDPR and Cookie Law were created for big corporations to legitimise data trade where before it was grey area. Now they get consent as people blindly click accept and they can make money. It was never about privacy.

If it was about privacy they would simply make all tracking and profiling opt in.

Re: I'm reluctant to verify my identity or age for any online services

#394

Earlier quoted context omitted.

First of all, if you don't practice any tracking limitation, you're almost certainly giving additional parties (directly or otherwise) access to your personal information. This is marketing data brokerage, this is the whole ballgame. To your point about the actual harm, I've come to see it as a kind of ecological problem. Wasting energy and sending more trash to a landfill doesn't harm me individually, at least not i…

Sadly, this still doesn't do anything to show me that I should opt out. I, as an individual, am not going to have any effect on a business if I opt out or not. No business decision is going to be made because I opt out. You might argue that it will matter if enough of us do it. Sure, that is true... but again, it won't matter if I do it or not. If N number of people opting out is enough to ruin the business model, th…

Potential real-world consequences, while they do exist, are simply too subtle to realize. Some actual examples of cookies being used against people:

- CBP has admitted to buying location/advertising data from brokers to use in helping locate people to arrest

- Phishing and identity theft can be made easier due to cookies... security researchers have even demonstrated 2FA bypass techniques based on it

- Price discrimination - Consumer Reports found that flight prices can fluctuate based on your cookies. Sometimes they would even raise the price if you kept searching for routes, as an indication that you were in a hurry, thus likely willing to pay extra.

- Healthcare discrimination - Companies have been found to raise healthcare prices or deny coverage due to cookie data aggregated via brokers where external sites tracked a person's health conditions based on what pages they visited (examples: fertility, cancer and mental health support groups)

- AI models or automated systems using cookie data to predict housing stability, creditworthiness, and employment risk without ever seeing your resume or credit report directly

- ProPublica found that Facebook was allowing advertisers to target their housing ads based on specific age/race groups stored in cookies

- Some recruiting firms have used cookies to infer personality traits and political leanings. Your employment application could be rejected or deprioritized based on that

- Based on the previous examples, I think it is not a far-fetched idea that websites and services could deny you access altogether based on data revealed by a combination of things like your browser fingerprint + brokered cookie data, such as political affiliation, estimated income, race/gender, health situation, etc. Imagine for example, not being able to order pizza because you badmouthed their favorite president online.

It's also harder to change your mind later and go delete a bunch of specific cookies to opt out when you could have just said no from the beginning.

Re: I'm reluctant to verify my identity or age for any online services

#395
I simply do refuse such systems, so far using decentralized or distributed socials like Nostr, Lemmy (self-hosted) and VPNs as glorified proxies and that's just because there aren't enough co-Citizens to impose a significant change with a national general strike enduring as much as needed to makes the government RUN, literally, to avoid lifetime jail...

Re: I'm reluctant to verify my identity or age for any online services

#396

Earlier quoted context omitted.

I am in my mid forties, been working as a professional software developer for over 20 years. I click “accept the cookies” almost every time. I just personally don’t feel it’s worth the effort and cost to try to avoid it. What “dark pattern cookie trick” are you worried about? I just can’t come up with a scenario where it will actually harm me in any way. All the examples I have heard are either completely implausible…

"software developer" is pretty broad. Here this is specifically B2C (business to customer) applications. I only assume that you haven't been in this market sector, otherwise you would've been more familiar with GDPR and all the concerns that prompted it. There was a time where the Internet was the wild west and you could've easily been personally targeted and exploited. Businesses sold your data to whoever. Even toda…

I am familiar with the GDPR. We had to do a lot of research when it came out (as well as the California version, the CCPA, where I live), and had to make some changes to how we dealt with data.

> There was a time where the Internet was the wild west and you could've easily been personally targeted and exploited. Businesses sold your data to whoever.

Yes, I remember when the internet was a much more dangerous place, in all sorts of ways. Browsers were not as secure, network security was not very robust. Most things were plain text. Hell, my friends and I used to run ettercap in our college dorm, because the entire dorm LAN was unprotected from ARP spoofing. Everything was sent in plain text, we would capture email passwords, AIM passwords, etc. We would play pranks on each other where we would spoof AIM messages to different people pretending we were someone else on the dorm floor.

I think some of the regulations have helped the internet be safer, but the tech is really what has changed.

Re: I'm reluctant to verify my identity or age for any online services

#397
post #374
post #78

Earlier quoted context omitted.

What would a safe extension model look like to you? At some point, you have to implicitly trust someone unless you audit every line of code (or write it yourself) and build everything from source that you run.

> What would a safe extension model look like to you? > At some point, you have to implicitly trust someone A model so I trust my OS and my browser, and I don't have to trust anyone else, that is, they can't harm me.

You need open source extensions (they are now, as the source is included) and you need to personally audit them, or you need to find a browser with every single feature you want.

Or do you want the browser to enforce permissions on extensions so you can lock them down as well as auditing them?

Re: I'm reluctant to verify my identity or age for any online services

#398
post #156

Earlier quoted context omitted.

It's solved if you trust Safari. I'm not sure that's the case for the parent poster.

So you don’t “trust” Safari but you trust Firefox? In 25 years absolutely no one has accused Apple of storing your browsing data that’s not e2e encrypted (its stored so it can sync across devices).

Did I say I trusted Firefox?

I'm not the person who wants to redesign the browser extension ecosystem, but I can build Firefox from scratch and review the source code if I want, unlike Safari.

Re: I'm reluctant to verify my identity or age for any online services

#399
post #6

I was sitting in a room the other day with a young adult, we were searching for additional algorithm learning materials. They searched in Google, and accept the cookies. They clicked on a website, and accepted those cookies too. They then started entering their email address to access another service. I was completely taken aback. I'm the sort of person that either rejects the cookies, or will use another site entire…

> It is the young people that are growing up conditioned to press accept It's really alarming, actually. I run the cyber security training & phishing simulations at my work, and it's the younger employees that struggle the most. It's like they just assume that everything on the web is trustworthy. It's not hard to see why though. They grew up with app stores & locked down devices. No concept of a file or file system,…

In some sort of weird sense, it makes me appreciate the 'free armor trimming', 'alt F4 helps block attacks in pvp', and similar people in RuneScape. It gave young me a very low stakes environment to learn about scams, losing only what amounts to a little bit of my time. I wonder if there is an argument that we should encourage a certain level of scamming in video games just for the lessons it teaches at low cost? Alas, this isn't generalizable to society at large.

Re: I'm reluctant to verify my identity or age for any online services

#400

Earlier quoted context omitted.

So exactly which of “your actual files” do you need access to?

The Files app cannot access images in the Photos app or music in the Music app. The only way to add music to the Music app is to copy the files onto the iPhone from a computer. You can however install VLC player and copy the files into the VLC folder. I guess VLC player is more trustworthy than Apple Music considering it's less isolated. Or Apple really wants you to pay the Music subscription, who knows. Want to give…

That’s a fair point. I was expecting the typical HN geek answer that you can’t access system files on iOS and you don’t have root access
Post reply on HN