Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

621–630 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#621

Earlier quoted context omitted.

> if they want to force this... or they want to make everyone accept it with some "crisis argumentation". False dichotomy, both parts are equivalent.

I'm not sure if you are agreeing or disagreeing? Or are you discussing a semantic thing?

The latter.

They are going to force it by creating artifical problems, waiting for the public's reaction and coming up with prefabricated solutions.

Every little incrementalist step that led us to the current state of affairs, was implemented this way.

Re: The 'papers, please' era of the internet will decimate your privacy

#622
post #454

Earlier quoted context omitted.

But ... you were arguing method X prevents this from "They become a traceable identity token". And what are you going to do with the anonymous tokens? You'll identify whose credentials they are ... If you can identify physical hardware from a request or post, obviously it's not anonymous. In fact, if you can identify the owner of credentials from the credentials, they're not anonymous. Obviously in an actual anonymou…

No, you don't look up the token. You check a zero-knowledge proof. The way this works is, there's a function with both public and private inputs, and an output. You can send me public inputs, and I can pass those plus my private inputs into the function, and give you the function output, along with a proof that the output is correct given your inputs. So in this case, the government has a public key, which it uses to…

So now you drop the other demand. If someone is caught faking credentials, remotely, what do you do? Because if you don't identify whose credentials they are proxying (just send the random number to an actual adult's phone and return the "generated proof") will mean everyone bypasses the security.

Which means your effectiveness is nothing if you have actual anonymity, because you can't catch who proxies. So you have a critical problem one way ... AND the other way.

Re: The 'papers, please' era of the internet will decimate your privacy

#623
post #314

Earlier quoted context omitted.

I think their point is to protect kids who have parents so tech illiterate they do not know how to manage parental controls. Having seen some parents I kind of believe it but not to the point of wanting to implement ID tracking on everything.

You've got to be really on the margin of society to not be able to set it up when every grandma and her dog use smartphones. There're about 1000 different ways to improve the lives of such people without making everyone use their government ID when scrolling Instagram.

Using smartphone in itself doesn't mean anything, especially when a lot of people ask assistance to someone else whenever something change on their smartphone.

Re: The 'papers, please' era of the internet will decimate your privacy

#624

Earlier quoted context omitted.

> but if a minor is caught using someone's credential, then the person whose credential they are using can be investigated, and, if necessary, charged with a crime roughly equivalent to providing alcohol to a minor. Without the possibility of real world enforcement, none of these identity solutions can possibly work. They don't work even then. Suppose you completely eliminate privacy on the internet and require every…

> Is the child going to inform on themselves? No. Is the adult, when they don't even know about it? In the context of social media, if they want to actively participate they have to given that it's the entire point. It's true that even with a government ID scheme people could borrow someone's ID to get passive access with their consent. But a kid couldn't share an account with a parent without that parent knowing bec…

> In the context of social media, if they want to actively participate they have to given that it's the entire point.

If the kid signs up for e.g. TikTok and the adult neither uses nor has any intention of using that platform, what causes them to even notice that it's happening?

Social media also seems like a pretty obvious case for this not working at all because if you ban kids from the ones based in your country, they'd collectively sign up for one based in a different country that doesn't enforce the ban, and the network effect for that age group shifts there because of the ban.

> It's true that even with a government ID scheme people could borrow someone's ID to get passive access with their consent.

That seems like the main problem though? Even if it actually prevented them from posting, you're conceding that it neither prevents them from doom scrolling nor accessing pornography, which are both passive consumption.

Re: The 'papers, please' era of the internet will decimate your privacy

#625
post #172

Earlier quoted context omitted.

None of this is necessary. First, the only devices that actually need to be gated are cell phones. The user agent should simply send the user’s age of the parental lock is set up and the websites required to respect this. Parental controls and the OS should be robust enough to not let kids bypass it (e.g.: by installing a browser that skips the header, or blocking proxy websites) Done. Cellphones only because those a…

Never underestimate the resolve of a teenager who is being kept from something they want. And once they solve it, they will spread the word for clout.

I’ve been there and done that, as a teenager. However that was on a computer, mobile devices are much more restricted and more secured. If there is some arcane hack to bypass these it will be known and fixed.

For me the main goal is to go from “any kid can do whatever on internet, unsupervised” to “it takes effort and subterfuge to get to some stuff”.

Re: The 'papers, please' era of the internet will decimate your privacy

#626
post #622

Earlier quoted context omitted.

No, you don't look up the token. You check a zero-knowledge proof. The way this works is, there's a function with both public and private inputs, and an output. You can send me public inputs, and I can pass those plus my private inputs into the function, and give you the function output, along with a proof that the output is correct given your inputs. So in this case, the government has a public key, which it uses to…

So now you drop the other demand. If someone is caught faking credentials, remotely, what do you do? Because if you don't identify whose credentials they are proxying (just send the random number to an actual adult's phone and return the "generated proof") will mean everyone bypasses the security. Which means your effectiveness is nothing if you have actual anonymity, because you can't catch who proxies. So you have…

So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being.

If we're ok with "mostly fix it but if a few teenagers get through it's not the end of the world," then there are a few simple measures that could help a lot:

- Keep an eye out for any credentials posted online, and put those on the revocation list.

- Keep expirations short (and auto-renew).

- Keep the credentials in phone secure enclaves and USB hardware "wallets."

- Consider including private information like name/dob/ssn or credit card number in the credentials, so users have good reason not to share. (We could consider making USB hardware optional if we do this.)

Given secure hardware it might be possible to prevent proxies entirely, the same way we prevent other MITM attacks.

Failing that, we could start by making it illegal to run proxies. Installing a proxy on your phone would mean getting an app from a criminal, not checked by an app store, and giving the criminal a way to pay you. I wouldn't expect this to happen much. Installing on a computer, using a VPN, taking payment via anonymous cryptocurrency, sure, if the VPN isn't compromised. But I wouldn't expect all that many people to do all this. Generating the proofs is a bit expensive so you wouldn't have huge capacity per person.

Criminals in foreign countries could do it with stolen credentials, and they'd only need one. But our teenagers would have to pay a foreign company for the service, and for porn at least they could just pay a foreign porn site directly. For phones, the teenager would have to install an app to use the proxy, which is another dodgy untrusted app (on android, and not possible at all on iphone), and it's easier for parents to check what apps are on the phone than to check what websites the kid visits. And social media gets less appealing if a lot of your friends aren't on it.

If we want to lock things down harder we could go with criminal penalties for intentionally sharing your credentials, which I do not support, but would still be better than pervasive surveillance of everything we do online.

Requiring everyone to have secure cryptographic hardware would in one sense be annoying, but less so if we use it for other things too.

Re: The 'papers, please' era of the internet will decimate your privacy

#628
post #622

Earlier quoted context omitted.

So now you drop the other demand. If someone is caught faking credentials, remotely, what do you do? Because if you don't identify whose credentials they are proxying (just send the random number to an actual adult's phone and return the "generated proof") will mean everyone bypasses the security. Which means your effectiveness is nothing if you have actual anonymity, because you can't catch who proxies. So you have…

So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being. If we're ok with "mostly fix it but if a few teenagers get through it's not the end of the world," then there are a few simple measures that could help a lot: - Keep an eye out for any credentials posted online, and put those on the revocation list. - Keep expirations short (and auto-renew). - Keep the credentials in phone secu…

> So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being.

This is an argument about a crypto algorithm. If you somehow fix the mathematical problems I'll start checking how it behaves under ddos conditions and you best have a good answer. And I'm an amateur. With your attitude, I'd strongly advise against mailing the openbsd lists.

> Criminals in foreign countries could do it with stolen credentials, and they'd only need one. But our teenagers would have to pay a foreign company for the service, and ...

Indeed. You see the problem.

So now you're moving to making the system insecure (and obviously insecure). That was also not acceptable ...

You can have the system be:

* anonymous, but guaranteed to be insecure

* secure (or at least, as long as you get to use the police to go after "criminals"), but not anonymous

> If we want to lock things down harder we could go with criminal penalties for intentionally sharing your credentials, which I do not support, but would still be better than pervasive surveillance of everything we do online.

The only way to do this would be regular and surprise offline inspections of every device. Aside from being extremely impractical to do, it would also be much worse than online surveillance.

Re: The 'papers, please' era of the internet will decimate your privacy

#629

Earlier quoted context omitted.

The biggest angle for me is censorship. You associate your online identity with your legal identity, there is no longer any recourse if you are banned from a platform. You could easily be arrested if your posts are determined to be 'offensive' in some manner considered to be in breach of the law, or simply have no ability to rejoin a platform under a new identity, or have identities across multiple platforms banned i…

No matter what you do if you are on one of these platforms (this one included probably) they, Palantir and multiple other entities know you really are and where you live. Your defense against censorship and retaliation is not faux anonymity, but a functioning liberal democracy.

I'm not certain that local police forces are always consulting the NSA or Palantir to find out who is behind a particular account. I would guess that the vast majority of arrests for offensive posts were made openly under a real identity, with only the most extreme cases leading to a deeper investigation.

Re: The 'papers, please' era of the internet will decimate your privacy

#630
post #616
post #503

Earlier quoted context omitted.

> but this is also clearly a increased barrier. If there's a simple piece of software that can be installed, it's not meaningfully increasing the barrier. Also, there are negative consequences to introducing "rules that you're expected to break" like this. It makes the law unserious.

If it costs money that is definitely a barrier for a child. And apps can be as well, as a parent its easier to control what apps is installed than webpages visited.

Advertisers. Naturally someone who feels excluded or unable to compete on cleaner markets will offer the portal for people who don't have a regular id and if the ads on those portals do best if they are for toys then those are the ads they will sell.
Post reply on HN