Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

41–50 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#41
post #30

Earlier quoted context omitted.

I think even digital IDs will tend to exist as physical tokens? Also worth noting that you can have a digitized and cryptographically signed ID on "paper" which can serve much the same purpose (security, machine readability) as an electronic one. Where electronic tokens shine (for IDs or otherwise) is attesting to the physical possession of a single copy.

Many EU countries already issue a chipcard IDs which can be used to auth for government services (via NFC or a dedicated reader). So yeah, I'd expect those to move to a phone as an alternative to the card

This is not the same. For instance, we can access the internet without needing that ID. But right now there are attempts to force a digital ID in order to access information on the www - this is the whole idea behind "age verification". The kids are just used as excuse here. It has never been about the kids.

Re: EU Age Control: The trojan horse for digital IDs

#42

Earlier quoted context omitted.

I think even digital IDs will tend to exist as physical tokens? Also worth noting that you can have a digitized and cryptographically signed ID on "paper" which can serve much the same purpose (security, machine readability) as an electronic one. Where electronic tokens shine (for IDs or otherwise) is attesting to the physical possession of a single copy.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I doubt everyone will still be carrying phones as we know them in a decade, so we might indeed be headed for a future where governments keep giant databases of biometric information. Works OK if you trust your government to handle that properly and not abuse it in the future. The real headache is crossing borders, where your details end up in the hands of a foreign state.

Re: EU Age Control: The trojan horse for digital IDs

#43
post #24

Earlier quoted context omitted.

Is all data about you "surveillance". When your doctor produces a medical record after your visit, are they "surveilling" you? How about when the railway company stores your travels to bill you later? I'll assume your answer is no, and I that case surely you must see the value in that medical record being correct.

Are you equaling mass surveillance to a doctor keeping track of your health for diagnostic accuracy purpose ? Concerning the railway example, they only need to store how much I owe them, not my travels. Storing travel history on their end is already surveillance. Data keeping purpose and consents are what make something surveillance or not. Forcing every citizen to use ID to access the web is surveillance plain and s…

> Are you equaling mass surveillance to a doctor keeping track of your health for diagnostic accuracy purpose ?

No, I am legitimately asking to clarify your position, hence why I assumed you wouldn't call that surveillance. The point was for us to agree that the right to correct data is a meaningful and useful right to have.

Once we've clarified that, the rest of the arguments comes down on the separation of "surveillance" from "record keeping", a separation you attribute to "Data keeping purposes and consents". That aligns with current EU law, and I largely agree with treating that as a separation point. If you have a valid purpose, either by law or by duty to your customer, you get to keep records necessary to fulfill that need. I would note that these "duty to your customer" clauses are usually pretty broad and would, I imagine, allow the railroad company to keep and process your travel record for fraud prevention purposes.

The issue we encounter is what a valid "data keeping purpose" is, and if we trust our public institutions and infrastructure to govern that question. Especially when the potential data processors is a government agency. This I'm entirely uninterested in debating that question with a rando on HN. We likely live in two very distinct regulatory frameworks and have vastly different local governments. There's no basis for us to agree here.

I would however end by noting that the two clauses of your statement

> Data keeping purpose and consents are what make something surveillance or not.

and

> Forcing every citizen to use ID to access the web is surveillance plain and simple.

Are in tension with one another. Clause 1 opens up for the idea that there exists valid "non-surveillance" record keeping, and that the distinction of such record keeping from surveillance requires determination of consent and purpose. Clause 2 then foregoes that determination and just presupposes the argument. All ID checks are definitionally surveillance irrespective of purpose and consent.

In the current legal framework, government derives it's unilateral consent from the vote. If the law passes in a democratic system then it is, by that very process, a consensual and valid purpose.

Re: EU Age Control: The trojan horse for digital IDs

#44
post #33
post #10

With the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.

I think it has more to do with digital verification for social media in a hope of killing bot accounts that are interfering in the public debate. Some of the biggest social media influencer accounts turns out to be Chinese/Russian bots trying to fuel hate/division our democracies, and with LLMs it is only getting worse. Some form of digital ID to verify social media account identities is probably the only hope left o…

Then the politicians should be honest about this goal. The best way to solve a problem requires understanding what the problem is. If we pretend to solve another problem, the solution for the actual will be less than ideal.

Re: EU Age Control: The trojan horse for digital IDs

#45
post #33
post #10

With the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.

I think it has more to do with digital verification for social media in a hope of killing bot accounts that are interfering in the public debate. Some of the biggest social media influencer accounts turns out to be Chinese/Russian bots trying to fuel hate/division our democracies, and with LLMs it is only getting worse. Some form of digital ID to verify social media account identities is probably the only hope left o…

The bot problem is solvable by using a web of trust system. You don't need a digital ID for that (i.e. you don't need to tie your digital world identity to a real world identity, nor you need a central agency to manage these).

In web of trust, anyone could publicly certify who they know is a real person (i.e. validate a link from their id to another id). Then, if you received a message from someone, the system would find the path in the graph of real people you trust, to determine the trustworthiness of the source. So if the account is a bot, there would be no path from it to you in the trust graph.

The advantage is that everyone could supply their own subjective trustworthiness score, altering the graph. They could even publish it, so that other people could use trustworthiness assesment of accounts they personally trust.

The big issue with a system of web of trust is that it is too efficient, and just kills commercial advertising (and also propaganda). Because that is all about overcoming the natural web of trust that humans have.

Re: EU Age Control: The trojan horse for digital IDs

#46
post #42

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I doubt everyone will still be carrying phones as we know them in a decade, so we might indeed be headed for a future where governments keep giant databases of biometric information. Works OK if you trust your government to handle that properly and not abuse it in the future. The real headache is crossing borders, where your details end up in the hands of a foreign state.

What? What to replace the phones with? And why whatever replaces them wouldn't be able to do the same things?

Re: EU Age Control: The trojan horse for digital IDs

#47
post #10

With the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.

> Govts want to have control back

By forcing us to go through devices completely controlled by US companies?

Re: EU Age Control: The trojan horse for digital IDs

#48
post #47
post #10

With the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.

> Govts want to have control back By forcing us to go through devices completely controlled by US companies?

What are you referencing here?

Re: EU Age Control: The trojan horse for digital IDs

#49
post #33
post #10

With the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.

I think it has more to do with digital verification for social media in a hope of killing bot accounts that are interfering in the public debate. Some of the biggest social media influencer accounts turns out to be Chinese/Russian bots trying to fuel hate/division our democracies, and with LLMs it is only getting worse. Some form of digital ID to verify social media account identities is probably the only hope left o…

>Some of the biggest social media influencer accounts turns out to be Chinese/Russian bots trying to fuel hate/division our democracies

This is propaganda, none of those supposed networks exists or were successful in anything and when the media do show some supposed accounts they don't have a lot of views. Please stop falling for this, your democracy sucks because the politicians suck and the people want change so they turn to extremist parties.

Re: EU Age Control: The trojan horse for digital IDs

#50

It seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed. Also, remote attestation doesn't work that way and for good reason. Under a true ZKP system, a single defector (extracted/leaked/etc key) would be able to generate an infinite number of false attestations without detection.

> It seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed

This article is about EU age verification which is specifically and definitely stated as using zero knowledge proof in all technical docs that I've seen:

https://eudi.dev/2.5.0/discussion-topics/g-zero-knowledge-pr...

Post reply on HN