Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Age verification means identity verification.

Age verification means identity verification.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
45 Indlæg 19 Posters 75 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

    And to those that say that anonymity (or rather pseudonymity) can be implemented with zero knowledge proofs — yes. But that’s not what is being used in currently preferred age/identity verification „solutions“ which tend to be centralised, commercial offerings.

    2/2

    jimfl@hachyderm.ioJ This user is from outside of this forum
    jimfl@hachyderm.ioJ This user is from outside of this forum
    jimfl@hachyderm.io
    wrote sidst redigeret af
    #13

    @jwildeboer Exactly. There are combined technical/regulatory approaches which would allow for age (or any other legally mandated trait) verification that protects the user and are fairly straightforward to implement* in a setting of good faith interest by all parties. But that is not the setting we are in

    * (I have sketched out what such a technique might look like https://gist.github.com/jimfl/ff930632d9ee7dd68aeaa777ea714326)

    1 Reply Last reply
    0
    • jwcph@helvede.netJ jwcph@helvede.net

      @jwildeboer @michael Also, let's not forget that there is no way in hell any of these systems, however "secure" & "private" on paper, will not leak and/or abuse data. To believe anything else is literally to believe in magic.

      - so even if you don't believe that age verification = ID verification (which it is; there's no other way to do it), being against it still isn't dumb, but rather extremely sensible for this reason alone.

      michael@westergaard.socialM This user is from outside of this forum
      michael@westergaard.socialM This user is from outside of this forum
      michael@westergaard.social
      wrote sidst redigeret af
      #14
      There's absolutely ways to do it without id. At the simplest, issue everybody that's 18+ a certificate + key. The certificate can be issued without any identifying information. Have the site send a challenge to the user and have them sign that with their key and return the signed challenge + certificate. You've just proved they are 18+ without divulging any information and there is no risk for leaks at the site.

      It's a little more complex than that because it is very easy to use somebody else's key/certificate and the certificate itself can be used as a pseudonymous identifier if used directly against the site.

      This can be made decentralized (site decides which certificate issuers they trust) and can be made entirely offline.

      Just because sites now require uploading a picture of your passport or most government age verification mandates require something similar, doesn't mean it isn't possible to make it secure.
      kramse@helvede.netK jwildeboer@social.wildeboer.netJ 2 Replies Last reply
      0
      • michael@westergaard.socialM michael@westergaard.social
        There's absolutely ways to do it without id. At the simplest, issue everybody that's 18+ a certificate + key. The certificate can be issued without any identifying information. Have the site send a challenge to the user and have them sign that with their key and return the signed challenge + certificate. You've just proved they are 18+ without divulging any information and there is no risk for leaks at the site.

        It's a little more complex than that because it is very easy to use somebody else's key/certificate and the certificate itself can be used as a pseudonymous identifier if used directly against the site.

        This can be made decentralized (site decides which certificate issuers they trust) and can be made entirely offline.

        Just because sites now require uploading a picture of your passport or most government age verification mandates require something similar, doesn't mean it isn't possible to make it secure.
        kramse@helvede.netK This user is from outside of this forum
        kramse@helvede.netK This user is from outside of this forum
        kramse@helvede.net
        wrote sidst redigeret af
        #15

        @michael @jwcph @jwildeboer its a little more complex

        yeah, especially if you ignore all the rest. There are reasonas why we are fighthing stuff like #chatcontrol continously. I also lost count of what Crypto Wars we are at now

        So falling in a trap about tech, and looking at this as an academic problem to solve, is the first problem making your responses, well naive. Look at Denmark and our politicians

        Even if a perfect valid solution is proposed it will be subverted and twisted sooner or ltr

        jwcph@helvede.netJ michael@westergaard.socialM 2 Replies Last reply
        0
        • kramse@helvede.netK kramse@helvede.net

          @michael @jwcph @jwildeboer its a little more complex

          yeah, especially if you ignore all the rest. There are reasonas why we are fighthing stuff like #chatcontrol continously. I also lost count of what Crypto Wars we are at now

          So falling in a trap about tech, and looking at this as an academic problem to solve, is the first problem making your responses, well naive. Look at Denmark and our politicians

          Even if a perfect valid solution is proposed it will be subverted and twisted sooner or ltr

          jwcph@helvede.netJ This user is from outside of this forum
          jwcph@helvede.netJ This user is from outside of this forum
          jwcph@helvede.net
          wrote sidst redigeret af
          #16

          @kramse @michael @jwildeboer Also, *none of all that works if it can't be unequivocally tied to a specific person's identity*, which never can or will be secure or safe from abuse.

          How is this so hard to understand for some people?

          michael@westergaard.socialM 1 Reply Last reply
          0
          • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

            ADDENDUM: I said „final remnants“ because the ad/tracking mafia already has powerful capabilities to identify individuals with high probability of correctness. Avoiding their fingerprinting and correlation capabilities is almost impossible.

            zazzoo@mstdn.caZ This user is from outside of this forum
            zazzoo@mstdn.caZ This user is from outside of this forum
            zazzoo@mstdn.ca
            wrote sidst redigeret af
            #17

            @jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.

            violetmadder@kolektiva.socialV zenheathen@beige.partyZ drdrowland@fediscience.orgD 3 Replies Last reply
            0
            • zazzoo@mstdn.caZ zazzoo@mstdn.ca

              @jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.

              violetmadder@kolektiva.socialV This user is from outside of this forum
              violetmadder@kolektiva.socialV This user is from outside of this forum
              violetmadder@kolektiva.social
              wrote sidst redigeret af
              #18

              @zazzoo @jwildeboer

              Yes.

              That is precisely the entire point.

              1 Reply Last reply
              0
              • zazzoo@mstdn.caZ zazzoo@mstdn.ca

                @jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.

                zenheathen@beige.partyZ This user is from outside of this forum
                zenheathen@beige.partyZ This user is from outside of this forum
                zenheathen@beige.party
                wrote sidst redigeret af
                #19

                @zazzoo @jwildeboer This

                1 Reply Last reply
                0
                • zazzoo@mstdn.caZ zazzoo@mstdn.ca

                  @jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.

                  drdrowland@fediscience.orgD This user is from outside of this forum
                  drdrowland@fediscience.orgD This user is from outside of this forum
                  drdrowland@fediscience.org
                  wrote sidst redigeret af
                  #20

                  @zazzoo @jwildeboer

                  I agree. We must protect the ability to be anonymous on the Internet

                  1 Reply Last reply
                  0
                  • jwcph@helvede.netJ jwcph@helvede.net

                    @kramse @michael @jwildeboer Also, *none of all that works if it can't be unequivocally tied to a specific person's identity*, which never can or will be secure or safe from abuse.

                    How is this so hard to understand for some people?

                    michael@westergaard.socialM This user is from outside of this forum
                    michael@westergaard.socialM This user is from outside of this forum
                    michael@westergaard.social
                    wrote sidst redigeret af
                    #21
                    Then explain what won't work unless it's tied to a person's identity. Be specific.
                    kramse@helvede.netK 1 Reply Last reply
                    0
                    • kramse@helvede.netK kramse@helvede.net

                      @michael @jwcph @jwildeboer its a little more complex

                      yeah, especially if you ignore all the rest. There are reasonas why we are fighthing stuff like #chatcontrol continously. I also lost count of what Crypto Wars we are at now

                      So falling in a trap about tech, and looking at this as an academic problem to solve, is the first problem making your responses, well naive. Look at Denmark and our politicians

                      Even if a perfect valid solution is proposed it will be subverted and twisted sooner or ltr

                      michael@westergaard.socialM This user is from outside of this forum
                      michael@westergaard.socialM This user is from outside of this forum
                      michael@westergaard.social
                      wrote sidst redigeret af
                      #22
                      It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.

                      Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.

                      I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.

                      If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).

                      We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.
                      jwcph@helvede.netJ kasperd@westergaard.socialK 2 Replies Last reply
                      0
                      • michael@westergaard.socialM michael@westergaard.social
                        It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.

                        Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.

                        I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.

                        If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).

                        We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.
                        jwcph@helvede.netJ This user is from outside of this forum
                        jwcph@helvede.netJ This user is from outside of this forum
                        jwcph@helvede.net
                        wrote sidst redigeret af
                        #23

                        @michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.

                        What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.

                        Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.

                        jwcph@helvede.netJ michael@westergaard.socialM kramse@helvede.netK 3 Replies Last reply
                        0
                        • jwcph@helvede.netJ jwcph@helvede.net

                          @michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.

                          What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.

                          Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.

                          jwcph@helvede.netJ This user is from outside of this forum
                          jwcph@helvede.netJ This user is from outside of this forum
                          jwcph@helvede.net
                          wrote sidst redigeret af
                          #24

                          @michael @kramse @jwildeboer I wish you could see whose work you're doing here.

                          1 Reply Last reply
                          0
                          • jwcph@helvede.netJ jwcph@helvede.net

                            @michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.

                            What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.

                            Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.

                            michael@westergaard.socialM This user is from outside of this forum
                            michael@westergaard.socialM This user is from outside of this forum
                            michael@westergaard.social
                            wrote sidst redigeret af
                            #25
                            In the gun analogy, you're on the side of no gun control at all.
                            kramse@helvede.netK jwcph@helvede.netJ 2 Replies Last reply
                            0
                            • michael@westergaard.socialM michael@westergaard.social
                              Then explain what won't work unless it's tied to a person's identity. Be specific.
                              kramse@helvede.netK This user is from outside of this forum
                              kramse@helvede.netK This user is from outside of this forum
                              kramse@helvede.net
                              wrote sidst redigeret af kramse@helvede.net
                              #26

                              @michael @jwcph @jwildeboer

                              it was not me saying it was easy, we dont owe you anything #sealion

                              1 Reply Last reply
                              0
                              • jwcph@helvede.netJ jwcph@helvede.net

                                @michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.

                                What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.

                                Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.

                                kramse@helvede.netK This user is from outside of this forum
                                kramse@helvede.netK This user is from outside of this forum
                                kramse@helvede.net
                                wrote sidst redigeret af
                                #27

                                @jwcph @michael @jwildeboer 100 percent agree with @jwcph here

                                1 Reply Last reply
                                0
                                • michael@westergaard.socialM michael@westergaard.social
                                  There's absolutely ways to do it without id. At the simplest, issue everybody that's 18+ a certificate + key. The certificate can be issued without any identifying information. Have the site send a challenge to the user and have them sign that with their key and return the signed challenge + certificate. You've just proved they are 18+ without divulging any information and there is no risk for leaks at the site.

                                  It's a little more complex than that because it is very easy to use somebody else's key/certificate and the certificate itself can be used as a pseudonymous identifier if used directly against the site.

                                  This can be made decentralized (site decides which certificate issuers they trust) and can be made entirely offline.

                                  Just because sites now require uploading a picture of your passport or most government age verification mandates require something similar, doesn't mean it isn't possible to make it secure.
                                  jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                                  jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                                  jwildeboer@social.wildeboer.net
                                  wrote sidst redigeret af
                                  #28

                                  @michael Age verification is, in my opinion, labouring on the symptoms, while leaving the cause (platforms that due to lack of liability have put revenue over protecting minors) with consequences that go far beyond the "protect the children" mantra. It is like using a cannon to kill fly sitting on the church wall and with that taking the whole church down. @jwcph

                                  michael@westergaard.socialM 1 Reply Last reply
                                  0
                                  • michael@westergaard.socialM michael@westergaard.social
                                    In the gun analogy, you're on the side of no gun control at all.
                                    kramse@helvede.netK This user is from outside of this forum
                                    kramse@helvede.netK This user is from outside of this forum
                                    kramse@helvede.net
                                    wrote sidst redigeret af
                                    #29

                                    @michael @jwcph @jwildeboer

                                    if the solution ignores effectivity, and bad repercussions - like throwing anonymity away because of the children. It is NOT an acceptable solution.

                                    Dont focus only on expected good, but how can it be abused. Do you want to trust all future politicians with THIS power, and what happens WHEN data is stolen, be practical

                                    jwcph@helvede.netJ 1 Reply Last reply
                                    0
                                    • michael@westergaard.socialM michael@westergaard.social
                                      It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.

                                      Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.

                                      I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.

                                      If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).

                                      We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.
                                      kasperd@westergaard.socialK This user is from outside of this forum
                                      kasperd@westergaard.socialK This user is from outside of this forum
                                      kasperd@westergaard.social
                                      wrote sidst redigeret af
                                      #30

                                      My suggestion for how to address this is as follows:

                                      • Don’t let children have completely unrestricted internet access.
                                      • Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
                                      • We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.

                                      What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.

                                      I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:

                                      When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.

                                      Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.

                                      Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.

                                      jwcph@helvede.netJ 1 Reply Last reply
                                      0
                                      • kramse@helvede.netK kramse@helvede.net

                                        @michael @jwcph @jwildeboer

                                        if the solution ignores effectivity, and bad repercussions - like throwing anonymity away because of the children. It is NOT an acceptable solution.

                                        Dont focus only on expected good, but how can it be abused. Do you want to trust all future politicians with THIS power, and what happens WHEN data is stolen, be practical

                                        jwcph@helvede.netJ This user is from outside of this forum
                                        jwcph@helvede.netJ This user is from outside of this forum
                                        jwcph@helvede.net
                                        wrote sidst redigeret af
                                        #31

                                        @kramse @michael @jwildeboer - which means even if it worked, which it won't, and if it wasn't horribly invasive, which it is, and if it was secure, which it isn't, the potential for abuse is still so great as to make the "solution" unacceptable.

                                        1 Reply Last reply
                                        0
                                        • kasperd@westergaard.socialK kasperd@westergaard.social

                                          My suggestion for how to address this is as follows:

                                          • Don’t let children have completely unrestricted internet access.
                                          • Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
                                          • We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.

                                          What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.

                                          I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:

                                          When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.

                                          Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.

                                          Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.

                                          jwcph@helvede.netJ This user is from outside of this forum
                                          jwcph@helvede.netJ This user is from outside of this forum
                                          jwcph@helvede.net
                                          wrote sidst redigeret af
                                          #32

                                          @kasperd @kramse @jwildeboer @michael That's a lot of words just to say "I don't think we should hold the platforms making billions on endangering & harming our children responsible"...

                                          kasperd@westergaard.socialK argv_minus_one@mastodon.sdf.orgA 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper