Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

91–100 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#91
post #84
post #81

Earlier quoted context omitted.

I can't help but think people mean something else when they hear "digital ids" then what they are. Like I have a digital id from the government of the Netherlands that I use to log into their government systems to declare taxes or what not. I had an X509 certificate issued by Ukrainian government and have their app to do the same. It's bad somehow?

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

"They" will make it mandatory? Who is they?

How will the current approach result in total surveillance?

I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing.

Can you explain to me, how with an eID one would be prevented from communicating with anyone or buying food?

Re: EU Age Control: The trojan horse for digital IDs

#92
post #90

Earlier quoted context omitted.

Yeah, imagine if every convenience store had CCTV security filming everyone 24/7. Oh, wait...

they don't know necessary who are you and what are you buying. I don't think also for big shops with many customers that techonology and reliably do instance segmentation - this is not face id.

They don't, but there is a significant chance that their "security solution" uploads all the data to a cloud provider (Amazon, Google, Oracle) which will be more than happy to analyze the data for them.

Re: EU Age Control: The trojan horse for digital IDs

#93
post #91
post #84

Earlier quoted context omitted.

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

"They" will make it mandatory? Who is they? How will the current approach result in total surveillance? I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing. Can you explain to me, how with an eID one would be prevented from com…

> Can you explain to me, how with an eID one would be prevented from communicating with anyone or buying food?

Some government (will) make mandatory: social accounts (so also IM apps like IG, WA, X, messanger), banks, buying simcard, internet, buying alcohol, cigarettes, energy drinks).

Some companies will make it mandatory implicitly or explicitly just for profit: selling your consumption data, analytics for themselves. E.g. in poland it's harder and harder to pay with cash because reduced stuff and huge queues - they force your use self checking. The pricing changed also that you have to use their loyalty apps if you don't want to be ripped - otherwise you will be paying 50% more.

> I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing.

I don't like it either the problem is right now you mostly this being abused only in some hotels. Whats misleading that that this digital id won't allow tracking because you supposed to "trasmitting the bare minimum of identifiable information"

Re: EU Age Control: The trojan horse for digital IDs

#94

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

>You can already do that in the real world. This argument stays on the sand of inadequate analogy. The way that flaw is described in the story it allows industrialization of bypassing the feature. It's huge difference with the "real world".

The article is actually one of the better ones I've read. The technical analysis is somewhat above my head, but appears reasonable, and it is suggesting solutions in some cases rather than just dismissing the concerns of parents, and going full privacy nut about our democratically elected governments.

All i would say is that the solution doesn't need to be 100% effective. The same as real world "age gates" or ID verification (which is just some random person looking at your ID in most cases) are not.

The precedent set -- that everything online should NOT be immediately accessible to children -- provides parents (the ones that care at least) with some backup when trying to raise their children. Ultimately society as a whole is responsible children, and i don't want to live in a society that thinks it is fine for kids to scroll any content on social media and watch porn as soon as they are able to work out how to use a smartphone.

The replay attack mentioned may always be a loophole, I'm not sure. But any site hosting the replay attacks should be targeted for shutdown/blocking. The "source" ID must come from somewhere as well, so that could be a route to shutting them down (there are 100's of age verification requests against one ID each day, that's a bit weird...).

If parents are helping their kids bypass age gates or straight up don't care their 11 year old is watching porn, then there is not much to be done in that case. The key thing should be keeping the majority of children in compliance to give cover to the parents that do care. Not giving all the power to bad parents and social media companies as is the situation the moment.

Re: EU Age Control: The trojan horse for digital IDs

#95
post #90

Earlier quoted context omitted.

they don't know necessary who are you and what are you buying. I don't think also for big shops with many customers that techonology and reliably do instance segmentation - this is not face id.

They don't, but there is a significant chance that their "security solution" uploads all the data to a cloud provider (Amazon, Google, Oracle) which will be more than happy to analyze the data for them.

That's possible but would be completely and highly illegal, the EU regularly fines companies violating GDPR, and those fines are not trivial at all, they can be quite hefty.

Re: EU Age Control: The trojan horse for digital IDs

#96
post #83

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

The difference you barely have to show you physical ID - mostly only when interacting with bank, signing document, government. I never got asked when buying alcohol and if asked at least I would only let to have a look instead of snapping a picture. Imagine if suddenly every grocery, pharmacy, petrol station, parking place, restaurant, bar etc. now would ask you for your ID AND would snap a picture and store in their…

Why would they? The only reasons to show ID I can think of is when watching porn or maybe when buying alcohol online, though I doubt stores will want to risk driving customers away with that.

Re: EU Age Control: The trojan horse for digital IDs

#97
A digital ID not based on EU hardware should be taken down with prejudice. It's a direct threat to national security. US companies and, by extension, US government authorities have control over every popular endpoint (mobile phones, desktop OS).

Besides, if someone wants a digital ID, it already exists in many countries. Phones with NFC chips can read many passports, e.g. Germany has an "electronic passport" since 2005. It's barely used, though, because it's bullshit.

Re: EU Age Control: The trojan horse for digital IDs

#98

> Real cryptographic unlinkability schemes like BBS+ or CL signatures would produce uncorrelated proofs even on reuse. This is not that. This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+…

> Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives Yeah I'm getting really really tired of the "crying wolf" crowd

Just because the government is not out to get you at this exact moment doesn't mean that a future government won't be. Surveillance capacity seems to be a one way ratchet.

Re: EU Age Control: The trojan horse for digital IDs

#99
post #91
post #84

Earlier quoted context omitted.

The problem is what follows. They will make it mandatory to use the electronic ID to do anything, resulting in total surveillance. And if you happen to land on their "bad" list (which eventually everyone will), you're locked out of life completely. No banking, no traveling, no communication with anyone, no buying food, nothing.

"They" will make it mandatory? Who is they? How will the current approach result in total surveillance? I would much prefer hotels would have a scanner which just transmits the bare minimum of identifiable information from the ID instead of it being completely normalized in many countries/hotels that they take your ID card and scan the full thing. Can you explain to me, how with an eID one would be prevented from com…

Are you kidding right now? Have you seen what's happening with ICE in the US? EU countries are just one effective social media campaign cycle away from the same policies. "It can't happen here" is foolish thinking.

See also: CCP

Re: EU Age Control: The trojan horse for digital IDs

#100
post #75

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

> The digital wallet solution is an extension to that system that will allow foreign EU citizens to authenticate themselves more easily Is there a roadmap and/or a timeframe for that? I have a Slovak ID same as the author, when will it be useful for accessing internet services?

Age verification has taken about three or four years to reach the concept stage, and that's the first stage that will be rolled out.

The legal framework behind all this was released all the way back in 2014 and has been officially adopted ten years later.

Officially, by December 2026, each member state must have at least one official wallet solution available for its citizens.

That said, eIDAS 2.0 also mandated that, as of this year, whatever Slovak digital identity solution has been rolled out so far must also work in other member states. In my experience, different governments adopt different foreign identity services at different paces, most of them seemingly missing the deadline.

Banks and other private institutions permitted to ask for ID are supposed to accept the wallet solutions by late 2027.

I expect deadlines to be missed given we've barely gotten the age verification PoC done, but with the groundwork laid out, things might just work out.

Post reply on HN