Live data from Hacker News

The 'papers, please' era of the internet will decimate your privacy

expression.fire.org

631–640 of 655 posts

Re: The 'papers, please' era of the internet will decimate your privacy

#631
post #321

Earlier quoted context omitted.

Libraries track what books you read (nowadays via some database and in the past via paper)

They track what you lend, not what you read. Many people just read on location.

I guess it depends on the library.

When I was writing my masters thesesis most rare books had to be requested - they wpuld bring them from the archive.

The books you could freely take was mainly Stephen King and year 1 stuff.

They registered what you requested and returned (to prevent theft)

Re: The 'papers, please' era of the internet will decimate your privacy

#632
post #628

Earlier quoted context omitted.

So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being. If we're ok with "mostly fix it but if a few teenagers get through it's not the end of the world," then there are a few simple measures that could help a lot: - Keep an eye out for any credentials posted online, and put those on the revocation list. - Keep expirations short (and auto-renew). - Keep the credentials in phone secu…

> So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being. This is an argument about a crypto algorithm. If you somehow fix the mathematical problems I'll start checking how it behaves under ddos conditions and you best have a good answer. And I'm an amateur. With your attitude, I'd strongly advise against mailing the openbsd lists. > Criminals in foreign countries could do it with s…

I'm not sure what my "attitude" is but I'm being pragmatic. This is not a binary situation, where it's either perfectly secure or useless. If our society is not willing to do what you and I prefer and leave things entirely open, then perhaps it's good enough to make things more difficult for teens to access, rather than accept pervasive surveillance to make it impossible. If people think it will improve society enough if most teens stay off certain sites, then we can do that and maintain anonymity.

I'll note that you skipped over my point that even with a "perfect" system, teens could still pay foreign porn sites etc directly. And that using a proxy would require installing an untrusted app on the phone, which would be relatively easy for parents to monitor and could be prevented entirely on iPhone. And that we can probably fix proxies with secure hardware anyway.

And no, the police idea that I do not support would not require surprise inspections. It just requires careless teenagers to occasionally reveal their identities online, with enough evidence to convince a judge to issue a warrant. It's dumb to make a federal case out of this, but not as dumb as losing all privacy and anonymity online. And, as I mentioned, this is not something actually required to make the idea workable.

I'm not going to keep repeating myself so I think I'm done here unless you have a point I haven't addressed in previous comments.

Re: The 'papers, please' era of the internet will decimate your privacy

#633

Earlier quoted context omitted.

Bad parents are always gonna find an excuse. Honest to God when I think of my childhood if people would’ve just left me alone for 30 minutes, I would’ve had a much easier time. Turns out you don’t need to get into a great college to make a lot of money. If anything, my screwing around all day with video games has probably led to my great 6 figure career. There’s absolutely no way to implement age gates all over the i…

So if it were a genuine approach from an adult simply looking to protect children, what would it be? As I said at the beginning, I don’t think it’s a good solution, just the only one we have. Again, please incorporate the fact that children are, for the first time EVER, dumber than their predecessor generation. It is a literally unprecedented step backwards. Who cares if kids can access data about slave revolts if th…

The government could start by undoing cuts to food aid programs.

https://frac.org/hunger-poverty-america

>Children: 14.1 million children lived in households that experienced food insecurity, a slight increase from the 13.8 million children reported in 2023.

This is something the government can actually fix without eliminating the first amendment.

Rampant food insecurity in young people probably has more to do with declining test scores than social media.

Re: The 'papers, please' era of the internet will decimate your privacy

#636
post #94

Earlier quoted context omitted.

I wouldn't trust governments, today or in the future, to keep such a system private and I don't see a foolproof way of building some kind of audit mechanism into it to make sure the data is always truely private. I've also always been curious how a truely anonymous identity verification could possibly work. At best for age verification, I could be given some kind of token that would still have to verify my age and be…

> I've also always been curious how a truely anonymous identity verification could possibly work. You go to a store. You show the clerk your id and give him a quarter. The clerk pulls a scratch-off ticket from the front of a ticket tape. The ticket contains a token identifier. It's anonymous. The clerk or his POS system knows your name and age, but doesn't know your number. The vendor providing the tape doesn't know…

Are you proposing this convoluted system is how a govenerment regulated internet would function?

Re: The 'papers, please' era of the internet will decimate your privacy

#637

Earlier quoted context omitted.

> these systems expose you to coercion, extortion, blackmail, ID theft, etc. by criminals and immoral people I'd prefer to have safety from that regardless of privacy. I think privacy is a stopgap semi-solution to those problems that might lessen the pressure to actually solve them in a reasonable manner.

It is impossible to “solve” problems like this, only manage them intelligently. Human societies have certain failure modes that are constant across history, and it’s foolish to assume that you will ever fully eliminate them. This means that reducing potential methods of political repression (via privacy, for instance) is more critical than attempting to create an impossibly perfect, airtight system, at least if you c…

> Human societies have certain failure modes that are constant across history, and it’s foolish to assume that you will ever fully eliminate them.

Technology shapes every bit of human culture. Nothing is constant.

While I agree that solving anything 100% is rarely ever achieved, there should be, at some point, an ability to mostly solve things in multiple ways. Even some that don't utilize privacy.

Re: The 'papers, please' era of the internet will decimate your privacy

#638

Earlier quoted context omitted.

So if it were a genuine approach from an adult simply looking to protect children, what would it be? As I said at the beginning, I don’t think it’s a good solution, just the only one we have. Again, please incorporate the fact that children are, for the first time EVER, dumber than their predecessor generation. It is a literally unprecedented step backwards. Who cares if kids can access data about slave revolts if th…

The government could start by undoing cuts to food aid programs. https://frac.org/hunger-poverty-america >Children: 14.1 million children lived in households that experienced food insecurity, a slight increase from the 13.8 million children reported in 2023. This is something the government can actually fix without eliminating the first amendment. Rampant food insecurity in young people probably has more to do with d…

Unfortunately, this is incorrect. There has not been significantly increasing food insecurity since ~2004. This food aid problem was created incredibly recently, and is unlikely to have anything to do with the topic at hand at all. Please, try to stay on topic. I doubt you honestly thought that was the issue.

Re: The 'papers, please' era of the internet will decimate your privacy

#639
post #628

Earlier quoted context omitted.

> So as I've mentioned elsewhere, that depends on how much of a stickler we insist on being. This is an argument about a crypto algorithm. If you somehow fix the mathematical problems I'll start checking how it behaves under ddos conditions and you best have a good answer. And I'm an amateur. With your attitude, I'd strongly advise against mailing the openbsd lists. > Criminals in foreign countries could do it with s…

I'm not sure what my "attitude" is but I'm being pragmatic. This is not a binary situation, where it's either perfectly secure or useless. If our society is not willing to do what you and I prefer and leave things entirely open, then perhaps it's good enough to make things more difficult for teens to access, rather than accept pervasive surveillance to make it impossible. If people think it will improve society enoug…

Thinking about this further: it looks to me like we can fully prevent proxy attacks if we assume secure hardware handling the cryptography on the client side, and send an encrypted sessionid to the client after verification.

The reason is that:

- We send a random number from the server at the beginning which is associated with the session, so a proxy can't just replay the encrypted proof.

- We pass the server key into the proof, so a MITM attack would give the wrong server key to the client, and the real server wouldn't be able to verify the proof.

Then with each request the secure hardware can provide encrypt(sessionid, nonce).

Re: The 'papers, please' era of the internet will decimate your privacy

#640

Earlier quoted context omitted.

I'm not sure what my "attitude" is but I'm being pragmatic. This is not a binary situation, where it's either perfectly secure or useless. If our society is not willing to do what you and I prefer and leave things entirely open, then perhaps it's good enough to make things more difficult for teens to access, rather than accept pervasive surveillance to make it impossible. If people think it will improve society enoug…

Thinking about this further: it looks to me like we can fully prevent proxy attacks if we assume secure hardware handling the cryptography on the client side, and send an encrypted sessionid to the client after verification. The reason is that: - We send a random number from the server at the beginning which is associated with the session, so a proxy can't just replay the encrypted proof. - We pass the server key int…

This would not be anonymous and would allow website owners to uniquely identify the hardware used to authenticate.

So, once again: you can have a secure system XOR you can have anonimity.

Post reply on HN