Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

591–600 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#591
The 'papers, please' era of the internet will decimate your privacy

Others perhaps, not mine. I will not participate in the 3rd party madness. It will be local stores for me, private forums for the local community self contained within the ISP. At most I will add RTA headers to my private and semi-private sites that are already hard to reach by bots. Any process that involves 3rd parties or magic math is going to expose many people both adults and children to risk they did not consent to and that will harm them throughout the rest of their lives.

Re: The 'papers, please' era of the internet will decimate your privacy

#592
post #94

Earlier quoted context omitted.

I wouldn't trust governments, today or in the future, to keep such a system private and I don't see a foolproof way of building some kind of audit mechanism into it to make sure the data is always truely private. I've also always been curious how a truely anonymous identity verification could possibly work. At best for age verification, I could be given some kind of token that would still have to verify my age and be…

> I've also always been curious how a truely anonymous identity verification could possibly work. You go to a store. You show the clerk your id and give him a quarter. The clerk pulls a scratch-off ticket from the front of a ticket tape. The ticket contains a token identifier. It's anonymous. The clerk or his POS system knows your name and age, but doesn't know your number. The vendor providing the tape doesn't know…

The token is only valid for a day after use, so loss and transfer isn't much of an issue.

If A is buying the ticket and immediately transfers it to B, you could end up defeating the aspect-validation element of this system. That mechanism would be strongly analogous to a straw purchase for alcohol or firearms:

https://en.wikipedia.org/wiki/Straw_purchase>

The likelihood of a large black market for underage Internet access developing is probably low, but informal small-scale attacks would likely be possible, and perhaps attractive to those who could negotiate the transaction on others' behalf.

That said, the underlying mechanism you describe is a good one, and the objections raised so far here largely specious.

Re: The 'papers, please' era of the internet will decimate your privacy

#593
post #26
post #21

There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. Governments that are serious about age verification and individual privacy (which, doubtful they truly are) should agree on a protocol a…

>Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. If it's unlinkable, what's preventing someone from setting up a site that hands out anonymous tokens for anyone to use?

Effectively, a straw purchase attack:

https://en.wikipedia.org/wiki/Straw_purchase>

Re: The 'papers, please' era of the internet will decimate your privacy

#595

Who'd have guessed hitting the library would become an act of rebellious defiance

"You know what the most dangerous thing in America is, right? N* with a library card."

- Brother Mouzone / Ed Burns & David Simon, The Wire (2003) S2E10 "Storm Warnings"

The scene is apparently on YT, though ... you'll have to sign in to confirm your age to view it best I can tell:

https://www.youtube.com/watch?v=pCioIwagYxM>

(If this link works, you'll get the full unbowdlerised quote. For those unfamiliar with the series, the speaker is Black.)

Re: The 'papers, please' era of the internet will decimate your privacy

#596
post #474

Earlier quoted context omitted.

The article talks about the possibilities of malicious cloning of these tokens by third parties, but fails to identify the much more common use case, and one that makes this scheme useless for age verification. It's one thing to be concerned about someone stealing my credential, but another to prevent the transfer of these credentials, especially if they are limited use credentials. The entire point of age verificati…

Kids shred these schemes. The designers of them seem to forget that the social dynamics of the adult world are completely different - just one kid needs to figure out how to bypass the system, and the knowledge spreads like wildfire. Example: schools banned phones, so kids switched to talking over Google docs: https://www.theatlantic.com/technology/archive/2019/03/hotte... If we give parents better tools to limit and…

  > just one kid needs to figure out how to bypass the system, and the knowledge spreads like wildfire.
I'm surprised this is not obvious to people here on HACKER News.

When I was in high school we all learned about proxies and bypassed the school firewalls. You didn't have to know anything technical after a few people figured it out. Hell, even the teachers were in on it. I remember one wanted to know so he could check the lotto numbers lol.

It's an eternal cat and mouse game and the mouse is going to win. I agree that the right idea is friction but if people aren't aware that there's no clear win that's going you work even 80% of the time then we'll write the wrong laws and have the wrong idea

Re: The 'papers, please' era of the internet will decimate your privacy

#598

You're on HN. You likely have lots of extra money. Donate to FIRE: https://www.fire.org/donate Donate to the EFF: https://supporters.eff.org/donate Any others?

ACLU: https://www.aclu.org/>

EPIC (Electronic Privacy Information Center): https://www.epic.org/

Further lists:

Data privacy advocates and associations https://privacybee.com/data-privacy-advocates-and-associatio...>

Privacy Focused Organizations You Should Know About https://identityreview.com/18-privacy-organizations-you-shou...>

Privacy & Information Law Research Guide https://guides.ll.georgetown.edu/c.php?g=468955&p=3962183> (oriented more at research but some overlap)

Re: The 'papers, please' era of the internet will decimate your privacy

#599
post #462

The goal should be to not repeat Star Wars - new technology that gives power and advantages is always adopted by companies first, then governments, and then it’s used to subjugate people. In Star Wars you have the trade federation abusing little planets. Little planet leaders go to government for help and vote a more “strong” approach to government that will “fight for the little guy”. An authoritarian leader steps i…

It's not that the Internet is repeating Star Wars. It's that Star Wars was a fictitious allegory of what power and capabilities provide, and should serve as a warning of what might happen ... or is happening. (I'd hesitate to call The Force a technology per se, though there are other technologies portrayed in the series ... little of which I've watched since Ep. 4-6.)

Technology is a force multiplier, genenerally, and new technologies, after an initial period of disruption, tend to either be adopted by existing power elites, or form new power elites, often a combination of both. I've only come to realise this myself relatively late in the game.

It's instructive to revisit much of the early writing of the Internet. Much of that was strongly hagiographic and deludedly optimistic, but there were exceptions. Andrew J. Shapiro's The Control Revolution (1999) got far more right than wrong.

https://www.worldcat.org/title/41076267>

https://archive.org/details/controlrevolutio0000shap>

http://libgen.vg/book/index.php?md5=9CCE57E117DD4213F395FE07...>

Re: The 'papers, please' era of the internet will decimate your privacy

#600

Earlier quoted context omitted.

> I think that's the same option? Not quite. I'm suggesting that adoption could be forced if the major browsers refused to load sites that didn't include the tags regardless of whether or not parental controls were enabled. The end result would be that either your site included the tags or else it would not load without some sort of manual user intervention on every visit on windows, ios, etc. > leaving the open web…

> But the entire point here is that there would be a legal mandate for all sites to carry such tags. My point is that you don't even need to mandate it for all sites, and attempting to do is kind of specious based on the existence of foreign sites. Rather you can focus on mandating it for the large consumer-oriented sites, and this will create enough of a critical mass that a web browser with parental controls enable…

> small personal website operators shouldn't be in the position of being forced to determine whether the random stuff on their personal website is specifically suitable for 13+, 18+, etc.

Agreed, but I take that a step farther and apply it to all operators. It's one thing to have a tag "18+ in the US" for when an operator is reasonably certain that his content is not legal to provide to minors. But the vast majority of the time operators should not be expected to be legal experts and they certainly can't be expected to keep up with all the different jurisdictions of the world.

Keep in mind the motivating issue here is parents filtering the content that their children are routinely exposed to. Everyone will inevitably have different concerns and standards, ex no social media versus no user generated content whatsoever versus 1 hour of social media or games or whatever per day. It's content awareness that's missing here. Everyone with legal concerns already posts a disclaimer that you have to click through and if they really care they send the RTA header.

> attempting to do is kind of specious based on the existence of foreign sites.

If the major browser vendors require it to load a page at all then it immediately becomes a de facto global requirement.

> The difficulty with forcing some uniform mandate onto "all sites" is that the mandate has to be for tags that are faithfully stated

One of the tags would amount to "not applicable". If a bunch of small time operators would prefer to be blocked by default and not think about the content they post then they could coordinate to create their own tag for that. The first step is uniform adoption then after that governments can penalize noncompliance in the form of inaccurate tags. I don't expect the latter would be much of an issue in practice though. Most people aren't going to intentionally misconfigure something but lazily not bothering in the first place is all too common.

Post reply on HN