Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

91–100 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#93

Earlier quoted context omitted.

Then just get rid of the age gating and verification entirely because it's useless.

Other parents have different opinions to you about the value of this.

You're the one who said kids would be accessing age gated sites with their parents' credentials. You're the one who made the case that it's useless. Don't go back and forth on it lol

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#94

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

Can you give a brief explanation of how this is done with a zero-knowledge proof? That site is low information and painful to navigate, and it seems quite surprising to me that this is possible. ID verification, in the government sense, is ostensibly going to require matching an ID against a some other resource. If done locally then you can trivially spoof the result, akin to hacking a game, but if done remotely then…

https://blog.google/innovation-and-ai/technology/safety-secu...

Basically you can prove that you have an identification document and that a certain property is true without revealing anything else.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#95

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

Can you give a brief explanation of how this is done with a zero-knowledge proof? That site is low information and painful to navigate, and it seems quite surprising to me that this is possible. ID verification, in the government sense, is ostensibly going to require matching an ID against a some other resource. If done locally then you can trivially spoof the result, akin to hacking a game, but if done remotely then…

Most countries in the EU already have widely accepted identity proof apps mostly verified by the banks or the government itself. Once verified the identity app gets a certificate which is signed by the authority which issues the identity. We all know how that works as that’s how TLS works as well. The zero proof age check is based on verifiable credentials and the related verifiable presentation. Once you have a wallet with your identity it’s not hard to issue cryptographic proofs of some properties of your credentials, and age is a property of your identity credentials basically. To learn more about the technical details, search for the specifications I mentioned above: verifiable credentials, verifiable presentations.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#96
post #15

On top of the pretty bad article, HN finds the “can’t win” scenario again. There’s no age verification scheme that will survive “collusion”, that’s when the adult allows the minor to use validated credentials, devices, etc. And whatever more intrusive age verification schemes we come up with will also fail this but add the intrusiveness to ruffle even more HN feathers. We can have the constant face, fingerprint and D…

The first premise you are avoiding is that a child can misuse a phone. The second premise you are avoiding is that the government can define , for every child, what constitutes misuse. You are advocating thought crime. You do not have my support. My government cannot adequately manage responsibility for my cupboards. It therefore shall not have authority over them.

I replied to the content of the article and HN comments, not what you think I should have replied to. If anything you even failed to notice that I expect parents to do some of the parenting and not expect an app to magically do it all for them.

The government already defines what misuse is both for children and adults, defines responsibility for a lot of things even in your cupboard, and has been doing so for as governments have been a thing. And I don’t think you understand what “thought crime” is.

You won’t hear me say this too often but next time use an LLM to write your comments, any LLM will do, can only get better.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#97
post #15

On top of the pretty bad article, HN finds the “can’t win” scenario again. There’s no age verification scheme that will survive “collusion”, that’s when the adult allows the minor to use validated credentials, devices, etc. And whatever more intrusive age verification schemes we come up with will also fail this but add the intrusiveness to ruffle even more HN feathers. We can have the constant face, fingerprint and D…

The first premise you are avoiding is that a child can misuse a phone. The second premise you are avoiding is that the government can define , for every child, what constitutes misuse. You are advocating thought crime. You do not have my support. My government cannot adequately manage responsibility for my cupboards. It therefore shall not have authority over them.

Do you also refuse to show id when buying alcohol because the gubbernment does not have authority over what you may buy?

That's how you sound.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#98
post #95

Earlier quoted context omitted.

Can you give a brief explanation of how this is done with a zero-knowledge proof? That site is low information and painful to navigate, and it seems quite surprising to me that this is possible. ID verification, in the government sense, is ostensibly going to require matching an ID against a some other resource. If done locally then you can trivially spoof the result, akin to hacking a game, but if done remotely then…

Most countries in the EU already have widely accepted identity proof apps mostly verified by the banks or the government itself. Once verified the identity app gets a certificate which is signed by the authority which issues the identity. We all know how that works as that’s how TLS works as well. The zero proof age check is based on verifiable credentials and the related verifiable presentation. Once you have a wall…

Ah, and the sites (or whatever else) can then verify the key is valid locally? Assuming that is the case, that'd make for a surprisingly nice system, further assuming that the produced credential is not reversible. I'm highly cynical and so I expected it to be a backdoor for surveillance as it feels like most things under the pretext of 'won't anybody think about the children' are.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#99
It is "funny" to read every single time "to protect minors online" like there are no adult around them, while technically those technologies are by design to control every single human for online access. It is not because the words are well chosen to sound unpolitical, just for "security", that it make those law/technology not political. It is political.
Post reply on HN