Could we step back a little and maybe revisit the premise that we need the gov't to be protecting children to begin with? That's what parents are supposed to be doing.
No let's not. Let's actually create and maintain a society. There are still places in the world where you and your family can literally fend for yourself against nature and rival gangs and so on if you're just super attached to the concept though, it's not like this option has been foreclosed.
What we call "age verification" is actually mass surveillance
501–510 of 520 posts
Re: What we call "age verification" is actually mass surveillance
#502Earlier quoted context omitted.
What do you mean by "active parenting", and why is it unrealistic? (Do you mean something specific like HHS' Active Parenting™? https://preventionservices.acf.hhs.gov/programs/744/show )
With active parenting I meant parents thoroughly checking the sites their kids have access to. Nothing parents can shoulder these days in my opinion since it is a very technical and fast moving problem. Some parents could do it, but the vast majority probably wouldn't. Most approachable is the device having some kid mode. In this mode online platforms need to send a respective header to authorise the content as kid f…
Re: What we call "age verification" is actually mass surveillance
#503Earlier quoted context omitted.
> there is no single government id in the UK at the moment, they currently do not control my identity Wait, so you live in a country where there is no government that can provide an ID? How does it work when you travel abroad? Do you have multiple legal identities, with different names and nationalities, that cannot be individually tracked back to one government? > you specifically talked about an OS without user cha…
they provide passports for travel, driving licences for driving, national insurance number for taxes, but its not a single id that everyone is required to have there is no point in it being open source if i cannot modify and run it
I am not sure what point you are trying to make. The government controls your passport, your driving licence, your national insurance number for taxes, but because those are 3 different IDs, it doesn't count as "your government controls your ID"?
Feels like you're just nitpicking for the sake of it.
> there is no point in it being open source if i cannot modify and run it
Well I for sure hate the idea of remote attestation, I agree with you on that. I was just pointing out that saying "it's not possible to have remote attestation on an open source system" is wrong: it's possible, that's a big part of why "they" like remote attestation: because they have control even if you can tamper with your system.
Re: What we call "age verification" is actually mass surveillance
#504Earlier quoted context omitted.
How does this work without a phone? I do 99% of my computer work, like now, not on a phone. Do regular desktop and laptop computers have the same secure enclave feature?
No, none of the commodity pcs or laptops come close to what Apple iPhone or Google Pixel hardware offers. Some have some sort of the secure enclave but it's not as safe.
Re: What we call "age verification" is actually mass surveillance
#505Earlier quoted context omitted.
> Your ID is already controlled by your government In the US, there are no national IDs, each state is responsible for their own. Transitioning to a national ID is not even legal currently, it would require a constitutional amendment... and I think most people do not want that for multiple reasons.
I am not sure how that is relevant, rather than nitpicking. In the EU, there is no concept of EU ID, each country is responsible for their own. Still, there is a governing entity that is responsible for your ID and controls it. Unless a US state is not a "governing entity"? Though the head of a US state is called a "governor", right?
Even the REAL ID Act only mandated requirements for a license when used to enter government owned or regulated property, and states can still choose not to abide by it.
Re: What we call "age verification" is actually mass surveillance
#506Earlier quoted context omitted.
> This is covered by allowing for single-use credentials. They said There are proposed mitigations like issuing multiple sets of credentials or rotating them, but we're not going to get an infinite number of keypairs for every website or session in the secure enclave in practice. > Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. The comments you replied to omitted ma…
> The government would know what wallet requested each single use identifier Which only means that the government knows how many tokens each citizen consumes on average. They don't know where each identifier was used nor the exact timestamp unless each website communicates this to the government, and such a backchannel does not exist in the spec.
And governments investigated high electricity users as suspected marijuana growers. Would governments ignore high identifier use?
Re: What we call "age verification" is actually mass surveillance
#507Earlier quoted context omitted.
> No, thank you Yes, as a parent you should be able to say this! You should also be able to say other things like I want my kid to have full access to wikipedia. Or I do not want my kid to have access to Faceboot, including a special Faceboot4Kidz version that their corporate attorneys have declared is completely suitable for minors. My whole point arguing for client side controls is that it allows parents to express…
If you want to argue for client side controls, I’m on your side. I’ve expressed this opinion elsewhere in this thread. I’m well educastes on what remote attestation means, and I know it’s the status quo. But it is not required by law. And I’d very much like for it to continue being optional indefinitely, and not bundled with a different “save the children” law. More specifically, I don’t want to have to prove to the…
Yes, then we're coming from the same place here.
> I’m well educastes on what remote attestation means, and I know it’s the status quo
I wouldn't describe remote attestation as the status quo. I generally use the web from my libre desktop, and apart from all the constant nagwalls (Cloudflare et al), I can access sites just fine. Perhaps on many mobile apps it's become some kind of status quo ("Play Integrity" I think it's called?), but even mobile browsers don't do attestation (WEI, or whatever they've renamed it to these days), IIUC.
> But it is not required by law
This is a red herring. None of these laws are proposing to require remote attestation, but rather anything that puts the onus on big tech to "verify age" (aka verify identity) will eventually lead to it being de facto required, with no direct law required.
> More specifically, I don’t want to have to prove to the OEM that I’m an adult to unlock my bootloader or disable SecureBoot. Or, more realistically, I don’t want OEMs deciding it’s cheaper to stop offering that choice because they don’t want to risk unlocking the bootloader on a child’s device.
I'm right with you about the knife-edge we're currently teetering on, where what is a pragmatic system that "merely" has gotchas could get more restrictive at any time. But Google already requires you prove you're the device owner to unlock a bootloader, and far too many manufacturers already don't let you unlock. But if done right, then none of this really matters for the parental controls use case - rather when unlocking the bootloader erases the whole device, that is the flag that lets a parent know.
Re: What we call "age verification" is actually mass surveillance
#508Earlier quoted context omitted.
> The government issues an eID to your wallet I'll stop you right here. I don't want to be forced to use a government issued ID — one the administration can revoke at a whim, one that will certainly be backdoored by intelligence agencies including the ones they haven't told you yet — just so I can talk to my friends online. It's insanity that we are asking the state to regulate personal identity — and trust them with…
Don't you have a SIM card?
Re: What we call "age verification" is actually mass surveillance
#509Earlier quoted context omitted.
I am not sure how that is relevant, rather than nitpicking. In the EU, there is no concept of EU ID, each country is responsible for their own. Still, there is a governing entity that is responsible for your ID and controls it. Unless a US state is not a "governing entity"? Though the head of a US state is called a "governor", right?
I think the relevance is that there can be no requirement by the US federal government for states to support any particular technology, which makes age verification continue to be a state-specific unregulated free-for-all. Even the REAL ID Act only mandated requirements for a license when used to enter government owned or regulated property , and states can still choose not to abide by it.
Re: What we call "age verification" is actually mass surveillance
#510Earlier quoted context omitted.
I don't know about this, stores around me are scanning people's IDs to verify their age. I guess I could make an ID (not a counterfeit government ID) that uses the same encoding for the birthday.
They are scanning the PDF 417 barcode on the back. Here are the specs for what appears on the driving license/ID and how to read the barcode: https://www.aamva.org/getmedia/99ac7057-0f4d-4461-b0a2-3a553... They issue a new spec every 4 years.