Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

441–450 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#441
post #65

Earlier quoted context omitted.

As you say, it's doubtful governments want it to be private. So we should expect them to not use these kind of elegant solutions, and the public is generally not sophisticated enough to distinguish between the options already.

In what direction do the incentives point?

>In what direction

Checkpoint Charlie directly ahead, not that far down the road.

If you venture into No Man's Land you could be shot on sight.

Re: The 'papers, please' era of the internet will decimate your privacy

#442

Earlier quoted context omitted.

Yes, this is the part of the issue that is so frequently ignored: Anonymous age verification schemes are easily defeated through proxying because there wouldn't be any consequences for selling your tokens. "Install this app on your phone and we'll pay you $1 per day" and it will mint your anonymous identity tokens and send them off to kids who want to buy them. If there's no way to track the tokens, there is no possi…

> They become a traceable identity token Not if you use a challenge-response protocol where the client returns a zero-knowledge proof of age, where the proof incorporates a random string sent by the website. The traceable stuff is private information that the website never sees. If a minor is caught with it, then law enforcement has local access to the minor's hardware and can probably view the private data. At that…

> If a minor is caught with it, then law enforcement has local access to the minor's hardware and can probably view the private data.

And then what? You think the police are going to make a case out of getting a token blacklisted or start an investigation into the person who the token came from? Also confiscate their devices as part of the investigation? I guarantee that the token source will be someone in another state or another country or just a stolen ID being used to sell their tokens.

I can’t believe we’re getting to the point where we’re talking about sending the police to deal with cases where a minor is suspected of, what, accessing social media? To confiscate their device and do forensic analysis of the tokens on it?

Do you realize how insane this is getting? How does anyone think this is feasible, let alone a good idea?

Re: The 'papers, please' era of the internet will decimate your privacy

#443

Earlier quoted context omitted.

This doesn’t stop the scheme the parent proposes, where adults install some proxy on their device and challenges are responded to on the parent device. Then the private key never leaves the parent device and all the child device has is the proxy software, which could be set up to not log any identifier of the key that it used

Sure, but then you're partnering with someone you probably don't know to take payment for doing something illegal, and that partner knows your device and where to send the money. And if it's a phone app, it's not going to be on app stores and you already know the person giving you the app is a criminal. So you're installing an untrustworthy app to risk criminal charges, and the customers of this scheme are kids who m…

You’re missing the point. If the tokens are truly anonymous then none of this matters. There’s no way to discover or prove where the tokens came from. It could be someone in another country with stolen IDs, which are now a goldmine for minting tokens and selling on the internet.

So the schemes inherently add some traceability, which makes the tokens no longer actually anonymous.

This is the back door used to make the tokens double as ID tokens.

Re: The 'papers, please' era of the internet will decimate your privacy

#444

Earlier quoted context omitted.

Yeah great idea, having to get out your government ID every time you want to use a website.

A certificate could be anonymous and the website would only need to verify it against the born_before_2008_root_cert in 2026. You could issue has many certs as you want and all would have a validity of 1 year so that websites only have to install at the maximum 2 root certs.

I know but what I mean is it's a lot of hassle just to visit something. And many devices I have like my VR headset don't have an NFC reader to validate some govt ID.

Re: The 'papers, please' era of the internet will decimate your privacy

#445
post #428

Earlier quoted context omitted.

You say that as though it's a feature rather than a bug. Being able to have an anonymous SIM card is a useful privacy and security feature, to avoid things like "tell me the ID of everyone in the vicinity of this protest". (And that's one reason governments try to break that.)

My sympathies are increasingly with the Chinese model of development. So, yes, policies that confront the major challenge of our era – ensuring social harmony among the chaos of modern media and communications – are good features.

> ensuring social harmony among the chaos of modern media and communications

Harmony is another word for suppression of dissent, and that's the effect it'll have.

There's a long history of tools being promoted for one purpose and used for another. Tools supposedly intended to restrict "porn" get used to restrict LGBT healthcare and resources. Tools supposedly intended to promote "harmony" on social media get used to track down activists and protestors.

The obvious response to such overreach is to refuse to allow such tools to exist. It's not that the tools invite abuse; it's that all use of such tools is abuse.

Re: The 'papers, please' era of the internet will decimate your privacy

#446

Earlier quoted context omitted.

It always gets back to the evil Jews with some people and ideologies. Sheesh.

What you expect people to just ignore where a lot of this anti-privacy industry is based?

OY VEY

Re: The 'papers, please' era of the internet will decimate your privacy

#447
post #429

Earlier quoted context omitted.

> They become a traceable identity token Not if you use a challenge-response protocol where the client returns a zero-knowledge proof of age, where the proof incorporates a random string sent by the website. The traceable stuff is private information that the website never sees. If a minor is caught with it, then law enforcement has local access to the minor's hardware and can probably view the private data. At that…

> Not if you use a challenge-response protocol where the client returns a zero-knowledge proof of age, where the proof incorporates a random string sent by the website. Obviously it does. These $1 per-day apps are 24/7 online and so challenges can simply be proxied just the same as tokens. > ... law enforcement has local access to the minor's hardware ... This is a large part of what people, in practice, want to prev…

Are you saying such proxying apps exist now? Can you link a source for me?

Regarding my scheme:

The only way law enforcement should have access is if they show up and get the phone in their possession, with a warrant. Which could happen any time some teenager posts something without realizing it identifies them.

If the teenager has your full credentials, that's when law enforcement sees who you are, and can take whatever action we deem appropriate. I would think just revocation if you might have been hacked, more severe if it's clear you shared on purpose. Revoking credentials doesn't interfere with the person using the app for other purposes, or with any prosecution, and criminal prosecution doesn't rely on the perp having money; quite the opposite in fact.

If you install a proxying app for the challenge-response, you're installing an untrustworthy app from a criminal to take payment for a criminal scheme, with risk of prosecution if that criminal gets caught.

Nothing in society is perfectly secure. There are all sorts of ways that we allow some crimes and tragedies to happen because we know that preventing them would be even worse. There are good reasons that courts have long protected privacy and anonymous speech, even though we could solve more crimes without those protections.

Re: The 'papers, please' era of the internet will decimate your privacy

#448
First observation: if you use social media, your privacy is already decimated.

So the article is not really defending privacy; it's simply defending social media. (Under-16s are an important demographic they don't want to lose).

That said, the article is forced to concede:

> Australia does order that personal information collected for age verification “must be destroyed once all purposes have been met.”

Let's repeat:

Social media MUST DESTROY all personal information collected for age verification.

But let's be honest: if you really value your privacy, you shouldn't be using social media.

Re: The 'papers, please' era of the internet will decimate your privacy

#449
post #365

There is a real problem here to be solved. Whenever I speak to someone who's planning to vote Reform (UK hard-right party) their views are primarily shaped by seeing AI slop videos on TikTok/Instagram, showing immigrants doing crimes etc etc Reform will probably win the next election because of this, unless we find a way to make platforms manage the situation. Interesting example: https://www.londoncentric.media/p/lo…

The simplest cure, even though it is US law but would also benefit the UK, would be to repeal Section 230 safe-harbors when the platform uses an algorithm to curate content. If they are covered by the "safe harbor" then they are not responsible for the content. Otherwise, they'd be liable for libel/defamation/conspiracy stuff.

https://en.wikipedia.org/wiki/Section_230

A "safe harbor" is a section of the law where they basically say "as long as you do X, those other laws won't apply". https://en.wikipedia.org/wiki/Safe_harbor_(law)#

Re: The 'papers, please' era of the internet will decimate your privacy

#450

Earlier quoted context omitted.

It always gets back to the evil Jews with some people and ideologies. Sheesh.

What you expect people to just ignore where a lot of this anti-privacy industry is based?

That’s a funny way to spell the United States.
Post reply on HN