Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

611–620 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#611

Earlier quoted context omitted.

The article talks about the possibilities of malicious cloning of these tokens by third parties, but fails to identify the much more common use case, and one that makes this scheme useless for age verification. It's one thing to be concerned about someone stealing my credential, but another to prevent the transfer of these credentials, especially if they are limited use credentials. The entire point of age verificati…

> The highest friction version of this is that the credential ties to a real world identity somehow; maybe locked behind legal barriers, etc., but if a minor is caught using someone's credential, then the person whose credential they are using can be investigated, and, if necessary, charged with a crime roughly equivalent to providing alcohol to a minor. Without the possibility of real world enforcement, none of thes…

> Parents buy those phones, phones could easily have a "user is a minor" setting (and a flag sent to all the sites that want one)

That's basically the California law! I hope other states adopt the "ask nicely for age but no online verification." OS setup asks for birthday, but you can just say January 1.

I also thought it should just send the flag, but I've heard there's good reasons not to. There's normally an affirmative prompt from the user to agree to send the age bucket data.

Re: The 'papers, please' era of the internet will decimate your privacy

#612

Earlier quoted context omitted.

Crusades against sexually explicit material are certainly popular in some places. But these days I see a lot more talk about the developmental effects of parasocial media on kids. There’s a whole segment of buy-in there that didn’t exist before.

I don't see where I should sacrifice my freedoms to remain anonymous on the internet or MUCH more importantly, have control over my hardware and software just because parents can't do their job

Oh I’m not saying that pervasive mandated identity verification is good. I think people should be skeptical about its benefits, very wary about its downsides, presume bad actors are involved, and make proponents fight for every inch of buy in, no matter what their stated motivations are.

I also think that holding important ground involves understanding the terms of the argument, including the problems people say they’re trying to solve.

Re: The 'papers, please' era of the internet will decimate your privacy

#613
post #245

Earlier quoted context omitted.

So much bad speech / misinformation is not anonymous, look at the kind of stuff the US President, Admin, and Gov't are proud posting, or the left/right-wing influencers. Forcing "papers please" on everyone is not going to meaningfully change the situation (imo). It will give the autocrats an inch and then they will take more. Eventually they will be able to police online speech. --- From: On Tyranny by Timothy Snyder…

I am not obeying in advance. My privacy was obliterated with the government before I could even vote, with the data science of mega corps, and with the double digit number of times companies leaked my data based on have I been pwned numbers. I am not under the impression I have any sort of privacy on the internet anymore, other than from other regular civilians. What I have to deal with is bots, foreign actors, and d…

I see the movement brewing while out steilling the streets. Not the first time, not the last, it's all cycles

Re: The 'papers, please' era of the internet will decimate your privacy

#614
post #21

There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users. Governments that are serious about age verification and individual privacy (which, doubtful they truly are) should agree on a protocol a…

The article talks about the possibilities of malicious cloning of these tokens by third parties, but fails to identify the much more common use case, and one that makes this scheme useless for age verification. It's one thing to be concerned about someone stealing my credential, but another to prevent the transfer of these credentials, especially if they are limited use credentials. The entire point of age verificati…

> Keep dreaming of a technological solution -- there is none that does not lead to the world that FIRE is warning about, except to accept that we can only make a solution "good enough" and leave it at that, without expanding into full on identity verification.

The world that FIRE is warning about already exists in Australia, whose age verification laws prompted the article.

I'm an Australian. Our government passed the Assistance and Access bill on New Year's Eve in 2018, without much debate. The law allows them to demand "assistance" (code word for: you shall develop an undetectable spy app for us), and "access" (code word for: you shall silently install that app on the devices of any persons we nominate). Both requests are subject to a gag order.

As an example of what's possible, this allows them to demand Google "assists" them to develop an undetectable app that records the phone screen and keyboard usage at periodic intervals, and send it back to them, and then to demand Google installs it on devices owned by persons of interest.

The world has continued on. That may be because the tech bros are resisting helping (there were threats by a government head of security implying they weren't getting the level of compliance they wanted). But it may also be because we are a democracy, and blatant misuse of powers like this is likely to get you unelected. I've seen a few cases where it "felt" like the government bureaucracies used this tool against whistleblowers, which made me feel distinctly uncomfortable. But I don't know, and until recently they had a remarkably good track record against local terrorism. The recent exception is the recent Bondi killings, where a completely bonkers father convinced his son to go on a shooting spree. But they managed to maintain complete radio silence during the perpetration stage - I guess it was all planned over the kitchen table. That couldn't be detected by any surveillance network.

So for now, it looks like they have used the tool according to the rules laid down in the bill. All spying requires independent judicial orders, which I'm fairly sure they obtained. (To put that into perspective - when the threshold is "the person broke the law" and you get to write the laws, the threshold is not quite as high as it might appear - particularly for government whistleblowers that pissed off the incumbents.)

But for most of us, whose "crimes" are at most indulging in naughty pleasures, the bill offers pretty good privacy guarantees. If the government doesn't follow its own laws all bets are off, of course - and yes, this very scenario is playing out in another Five Eyes country. But if the government does follow its own rules, then any government-backed zero-knowledge proof scheme that includes a snitch code that can only be unlocked by a judicial order is going to be fine.

TL;DR: for the scenario FIRE is worried about, the horse bolted 8 years ago in Australia. The current alternative of being forced to hand over photos, identity documents, and god knows what other PII to random web sites is far worse in terms of privacy than a zero-knowledge proof of age issued by the government - even if isn't truly private.

Re: The 'papers, please' era of the internet will decimate your privacy

#615

Earlier quoted context omitted.

It is such a sick idea. But i cant really figurer out if they want to force this on us or they just anticipate that type of poverty will become normal for the new "middle class" and they want to make everyone accept it with some "crisis argumentation".

> if they want to force this... or they want to make everyone accept it with some "crisis argumentation". False dichotomy, both parts are equivalent.

I'm not sure if you are agreeing or disagreeing? Or are you discussing a semantic thing?

Re: The 'papers, please' era of the internet will decimate your privacy

#616
post #503
post #320

Earlier quoted context omitted.

I agree, but this is also clearly a increased barrier. Going back to OPs comment that perfection is impossible, the goal is to raise the bar, I would say that this is more than good enough.

> but this is also clearly a increased barrier. If there's a simple piece of software that can be installed, it's not meaningfully increasing the barrier. Also, there are negative consequences to introducing "rules that you're expected to break" like this. It makes the law unserious.

If it costs money that is definitely a barrier for a child. And apps can be as well, as a parent its easier to control what apps is installed than webpages visited.

Re: The 'papers, please' era of the internet will decimate your privacy

#617

This just legitimises the existing practices. They already know who you are.

Hilarious. So if they know, then why all the fuss and the the need to enforce ID on the Internet? Just for the heck's sake? Ah, that's for legitimization. In other words, "by producing your digital ID, you herein fully acknowledge the fact that you're a slave to the system in which all we knew about you illegaly, is now known legally"?

It was tongue-in-cheek, a bit of satire :)

Re: The 'papers, please' era of the internet will decimate your privacy

#618

Earlier quoted context omitted.

There is a way to prevent this (or at least slow it down), but that way requires device integrity protection. With integrity protection, tokens can only be minted with a government app, driven by both biometrics and physical human hands touching the physical screen. There's no way to do it in the background. Without it, you can indeed have a single activist mint 10 billion tokens and give them out for free, defeating…

What you conveniently forgot to mention is this means the death of open general purpose computing. No more rooted devices, no more self built PCs. You go buy a government approved device and run the government approved OS preinstalled and the moment you deviate from the government approved happy path you are booted off the internet.

I didn't "conveniently forgot to mention" this. In fact, that was my entire point.

There is a tradeoff here. No matter which path we choose, we are going to lose one of the three legs of the triangle. We're currently losing age assurance, some members of society think that we're making the wrong tradeoff and that we should be making a different one, as is their right. Other members of society disagree, as is also their right.

I am intentionally not presenting an opinion on which tradeoff we should be choosing, I merely want to show that there is a tradeoff, and that whatever choice we make, that choice comes with consequences which we should be aware of and take seriously instead of dismissing entirely.

Re: The 'papers, please' era of the internet will decimate your privacy

#619
post #605

Earlier quoted context omitted.

What you also get is mobile devices that can't run unblessed code, make it impossible to remove legally-mandated spyware or backdoors, as well as websites that you can't use anonymously, even when you have very valid reasons to do so.

You also can’t build a house which violates building or electrical codes, or drive without a license. These are safety and security protocols and the digital realm now has them. Mobile devices are secure and that’s why they’re not infected with malware, like any Windows machine. This is why Android is the host of 98% of all mobile malware and iPhone is not. You have the freedom to make your own insecure devices which…

That's just it - if remote attestation becomes commonplace, you can't make your own devices. No apps you need to live your life will work, no mainstream websites will let you visit them... Not to mention that once you get to hardware, "just build your own" login simply stops working.

The internet has plent, of security elements. Devices use TLS to communicate, are encrypted by disk encryption, users' messages/calls/data are encrypted with various protocols... This is already in place.

Building codes and such are laws, the government didn't go and change the laws of physics to make it impossible to build something not up to code. They also don't limit the same of materials and tools to only certified builders who they know will respect the code. You can still break the rules to some extent, or even follow them, just without external certification.

Remote attestation and related technologies change the laws of physics - not complying is simply not possible. You can't just make one little change and hope nobody bothers you about it, the system makes the change impossible, or it detects it and "burns the whole house down".

If your house isn't certified because you repaired a light fixture on your own, you can still invite friends over, you can receive mail and packages to it, you can get phone, internet and other utilities. If you want to change the color of the icons on your phone, or if you want to disable the pre-installed spyware, you're cut off from talking to your firends and family, from social networks, reading the news, you can't pay your taxes, can't get a bank account, can't get paid for your work or even apply for a job. That is the reality we're going towards.

The thing that changes isn't that your every action will be followed. That already happens. It's that you are powerless to avoid it. It's a technological lock to keep you obedient. There is no security element to it. We as an industry need to stop pretending like these are security technologies and start talking to more social sciences experts. Before it's too late...

Re: The 'papers, please' era of the internet will decimate your privacy

#620

Earlier quoted context omitted.

Hilarious. So if they know, then why all the fuss and the the need to enforce ID on the Internet? Just for the heck's sake? Ah, that's for legitimization. In other words, "by producing your digital ID, you herein fully acknowledge the fact that you're a slave to the system in which all we knew about you illegaly, is now known legally"?

It was tongue-in-cheek, a bit of satire :)

Sorry then, I failed to parse it :)
Post reply on HN