Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Age verification means identity verification.

Age verification means identity verification.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
45 Indlæg 19 Posters 75 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • michael@westergaard.socialM michael@westergaard.social
    It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.

    Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.

    I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.

    If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).

    We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.
    kasperd@westergaard.socialK This user is from outside of this forum
    kasperd@westergaard.socialK This user is from outside of this forum
    kasperd@westergaard.social
    wrote sidst redigeret af
    #30

    My suggestion for how to address this is as follows:

    • Don’t let children have completely unrestricted internet access.
    • Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
    • We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.

    What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.

    I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:

    When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.

    Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.

    Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.

    jwcph@helvede.netJ 1 Reply Last reply
    0
    • kramse@helvede.netK kramse@helvede.net

      @michael @jwcph @jwildeboer

      if the solution ignores effectivity, and bad repercussions - like throwing anonymity away because of the children. It is NOT an acceptable solution.

      Dont focus only on expected good, but how can it be abused. Do you want to trust all future politicians with THIS power, and what happens WHEN data is stolen, be practical

      jwcph@helvede.netJ This user is from outside of this forum
      jwcph@helvede.netJ This user is from outside of this forum
      jwcph@helvede.net
      wrote sidst redigeret af
      #31

      @kramse @michael @jwildeboer - which means even if it worked, which it won't, and if it wasn't horribly invasive, which it is, and if it was secure, which it isn't, the potential for abuse is still so great as to make the "solution" unacceptable.

      1 Reply Last reply
      0
      • kasperd@westergaard.socialK kasperd@westergaard.social

        My suggestion for how to address this is as follows:

        • Don’t let children have completely unrestricted internet access.
        • Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
        • We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.

        What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.

        I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:

        When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.

        Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.

        Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.

        jwcph@helvede.netJ This user is from outside of this forum
        jwcph@helvede.netJ This user is from outside of this forum
        jwcph@helvede.net
        wrote sidst redigeret af
        #32

        @kasperd @kramse @jwildeboer @michael That's a lot of words just to say "I don't think we should hold the platforms making billions on endangering & harming our children responsible"...

        kasperd@westergaard.socialK argv_minus_one@mastodon.sdf.orgA 2 Replies Last reply
        0
        • michael@westergaard.socialM michael@westergaard.social
          In the gun analogy, you're on the side of no gun control at all.
          jwcph@helvede.netJ This user is from outside of this forum
          jwcph@helvede.netJ This user is from outside of this forum
          jwcph@helvede.net
          wrote sidst redigeret af
          #33

          @michael @kramse @jwildeboer No - I'm in favor of removing the source of the problem, rather than making the effects of it the victims' responsibility.

          Get rid of guns, get rid of harmful platforms.

          (note I didn't say "get rid of harmful content", which would also be impossible - the problem here is platforms profiting wildly on serving harmful content in harmful ways & we have both the platforms' own words & the word of the courts on this)

          1 Reply Last reply
          0
          • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

            @michael Age verification is, in my opinion, labouring on the symptoms, while leaving the cause (platforms that due to lack of liability have put revenue over protecting minors) with consequences that go far beyond the "protect the children" mantra. It is like using a cannon to kill fly sitting on the church wall and with that taking the whole church down. @jwcph

            michael@westergaard.socialM This user is from outside of this forum
            michael@westergaard.socialM This user is from outside of this forum
            michael@westergaard.social
            wrote sidst redigeret af
            #34
            I don't think age verification is that intrusive. I think ID verification is. ChatControl and similar legislation is a nightmare because it doesn't make a clear distinction.

            I am very much against current versions, but am not so sure I would be against a version that stated clearly "age verification only, it is illegal to use a solution that allows tracing back to an individual." Would you? If the requirement were enshrined in the law, implementations would have to go beyond "password uploaded to ZenDesk" and the government cannot salami-slice their way into deanonymizing the entire internet.

            Only some platforms (SoMe) are bad because of profit. Roblox and Discord have other problems more related to lack of oversight of kids. Others I don't have a fully formed opinion about (a 16-years old should probably have access to the 'Hub, a 6-years old probably not).

            It would be good if SoMe were less shit, but I don't see a clear path to ensuring that. Preventing kids from having access to things their brains cannot deal with is an imperfect solution that works somewhat in the physical world (restricting access to alcohol, tobacco, and other drugs, e.g.). "Just forbid Facebook" or "never any age control" is not going to be convincing on their own IMO.
            1 Reply Last reply
            0
            • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

              ADDENDUM: I said „final remnants“ because the ad/tracking mafia already has powerful capabilities to identify individuals with high probability of correctness. Avoiding their fingerprinting and correlation capabilities is almost impossible.

              chbmeyer@digitalcourage.socialC This user is from outside of this forum
              chbmeyer@digitalcourage.socialC This user is from outside of this forum
              chbmeyer@digitalcourage.social
              wrote sidst redigeret af
              #35

              @jwildeboer good point. There already is no thing like "anomity" for the tracking industry or for secret services / states.
              It's just a feeling for the people and users.

              Current political discussions are leading in the wrong direction. You want to avoid an abuse that already is implemented in every day life.

              1 Reply Last reply
              0
              • jwcph@helvede.netJ jwcph@helvede.net

                @kasperd @kramse @jwildeboer @michael That's a lot of words just to say "I don't think we should hold the platforms making billions on endangering & harming our children responsible"...

                kasperd@westergaard.socialK This user is from outside of this forum
                kasperd@westergaard.socialK This user is from outside of this forum
                kasperd@westergaard.social
                wrote sidst redigeret af
                #36

                They should definitely be held responsible. But we don’t do that by handing them even more sensitive data after they have demonstrated that they shouldn’t have been trusted with the data that they already control.

                1 Reply Last reply
                0
                • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

                  Age verification means identity verification. And it removes the final remnants of anonymity from the internet. Anonymity in the sense of being in control of the decision to share your identity is however a requirement for a public space. The internet can never be a public space with identity verification. That’s what is at stake, in my personal opinion.

                  1/2

                  S This user is from outside of this forum
                  S This user is from outside of this forum
                  spacelifeform@infosec.exchange
                  wrote sidst redigeret af
                  #37

                  @jwildeboer

                  The fascists want ID so they can Dox, Swat, SLAPP, etc those that say mean words that hurt their fee-fees.

                  #FirstAmendment

                  1 Reply Last reply
                  0
                  • michael@westergaard.socialM This user is from outside of this forum
                    michael@westergaard.socialM This user is from outside of this forum
                    michael@westergaard.social
                    wrote sidst redigeret af
                    #38
                    If you are right, then there should be no issue with requiring age verification if it implies no ID checks?

                    But you really can. You can decouple it so the information is spread around. I made a simple protocol that makes it impossible for the site to even pseudonymously track users, and makes it impossible for the government to track where you go. You can have multiple instances of each of the parties (including the Government), so leak of all data from any of them will not provide full information to all. The attestation chain can be made as long as desired, each step adding to privacy (requiring all to be compromised to fully identify the user). The government cannot see where (or even if) you use your age certificate. The attestor cannot see where you use it (the challenge is opaque) and if there are more attestors, they can only guess at how often you use it if you alternate in some unpredictable way. The attestor also cannot connect your request to your ID, but can build a pseudonymous profile on you. The site cannot build even a pseudonymous profile on you: it only has a signed challenge and the id of the attestor (which is picked by the user). If either attestor or site are fully leaked, the other can build a (partial) pseudonymous profile connecting your pseudonymous id to a single site. And the damage is reduced the more attestor and sites there are as each would have a smaller portion of the full data.

                    Given your name, I presume you know of eHerkenning and/or PKIoverheid? Both are digital government ID systems in the Dutch public sector. These have many of the features such an age verification system would/could use: there are multiple suppliers of eHerkenning certificates (similar to the government in my figure) and services providing validation of eHerkenning certificates (similar to the attestor in my figure). At the high assurance levels (eherkenning.nl/en/levels-of-assurance), you have to physically show your ID (they come to you, or you can go to, e.g., a KPN store). For eHerkeinning, this is done to make the ID very strong, but for age verification, this could be done to make sure there's no electronic trace between ID and certificate. Put the certificate on an NFC token or USB key in a sealed envelope and allow users to pick one at random. Doing this, would make it impossible for the government to reliably connect IDs to sites, even if both attestor and site were leaked.

                    And nobody NEEDs to store data (except perhaps for a limited time for auditing), and more importantly: nobody has a financial incentive to.

                    Alternatively, as @kasperd suggested elsewhere in the thread: include an age restriction in the data (can be as simple as a HTTP header) and leave the filtering to the client. That is even less intrusive as the parents would be in control of filtering.

                    Both of these allow age verification without allowing the final site to ID the user. Neither are fool-proof, but it's not fort knox, it's just guarding access to sites that are presently accessible to all.
                    jwildeboer@social.wildeboer.netJ 1 Reply Last reply
                    0
                    • michael@westergaard.socialM michael@westergaard.social
                      If you are right, then there should be no issue with requiring age verification if it implies no ID checks?

                      But you really can. You can decouple it so the information is spread around. I made a simple protocol that makes it impossible for the site to even pseudonymously track users, and makes it impossible for the government to track where you go. You can have multiple instances of each of the parties (including the Government), so leak of all data from any of them will not provide full information to all. The attestation chain can be made as long as desired, each step adding to privacy (requiring all to be compromised to fully identify the user). The government cannot see where (or even if) you use your age certificate. The attestor cannot see where you use it (the challenge is opaque) and if there are more attestors, they can only guess at how often you use it if you alternate in some unpredictable way. The attestor also cannot connect your request to your ID, but can build a pseudonymous profile on you. The site cannot build even a pseudonymous profile on you: it only has a signed challenge and the id of the attestor (which is picked by the user). If either attestor or site are fully leaked, the other can build a (partial) pseudonymous profile connecting your pseudonymous id to a single site. And the damage is reduced the more attestor and sites there are as each would have a smaller portion of the full data.

                      Given your name, I presume you know of eHerkenning and/or PKIoverheid? Both are digital government ID systems in the Dutch public sector. These have many of the features such an age verification system would/could use: there are multiple suppliers of eHerkenning certificates (similar to the government in my figure) and services providing validation of eHerkenning certificates (similar to the attestor in my figure). At the high assurance levels (eherkenning.nl/en/levels-of-assurance), you have to physically show your ID (they come to you, or you can go to, e.g., a KPN store). For eHerkeinning, this is done to make the ID very strong, but for age verification, this could be done to make sure there's no electronic trace between ID and certificate. Put the certificate on an NFC token or USB key in a sealed envelope and allow users to pick one at random. Doing this, would make it impossible for the government to reliably connect IDs to sites, even if both attestor and site were leaked.

                      And nobody NEEDs to store data (except perhaps for a limited time for auditing), and more importantly: nobody has a financial incentive to.

                      Alternatively, as @kasperd suggested elsewhere in the thread: include an age restriction in the data (can be as simple as a HTTP header) and leave the filtering to the client. That is even less intrusive as the parents would be in control of filtering.

                      Both of these allow age verification without allowing the final site to ID the user. Neither are fool-proof, but it's not fort knox, it's just guarding access to sites that are presently accessible to all.
                      jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                      jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                      jwildeboer@social.wildeboer.net
                      wrote sidst redigeret af
                      #39

                      @michael Yes, as I said in my second of two posts in the original thread, such systems exist. BUT they are not being used nor are they demanded by law. The current market for age verification is dominated by commercial entities that collect your identity data by requiring scans of passports, driver licenses etc. So whatever wonderful solutions exist (and they do), they are not the ones being used and promoted. So my point stands. @jwcph @kasperd

                      1 Reply Last reply
                      0
                      • slash909uk@mastodon.me.ukS This user is from outside of this forum
                        slash909uk@mastodon.me.ukS This user is from outside of this forum
                        slash909uk@mastodon.me.uk
                        wrote sidst redigeret af
                        #40

                        @jwildeboer @michael @jwcph @kasperd Can I add a thought here? All this talk is about 'age' as if that is the magic key needed to judge if a person is vulnerable and should be protected from potentially harmful information.

                        I suggest this should be more widely considered as a 'duty of care' responsibilty between a vulnerable person of any age and someone who takes care of them.

                        The carer needs both the tools and the cooperation of potentially harmful information providers to do their duty 1/2

                        slash909uk@mastodon.me.ukS 1 Reply Last reply
                        0
                        • slash909uk@mastodon.me.ukS slash909uk@mastodon.me.uk

                          @jwildeboer @michael @jwcph @kasperd Can I add a thought here? All this talk is about 'age' as if that is the magic key needed to judge if a person is vulnerable and should be protected from potentially harmful information.

                          I suggest this should be more widely considered as a 'duty of care' responsibilty between a vulnerable person of any age and someone who takes care of them.

                          The carer needs both the tools and the cooperation of potentially harmful information providers to do their duty 1/2

                          slash909uk@mastodon.me.ukS This user is from outside of this forum
                          slash909uk@mastodon.me.ukS This user is from outside of this forum
                          slash909uk@mastodon.me.uk
                          wrote sidst redigeret af
                          #41

                          @jwildeboer @michael @jwcph @kasperd IMHO regulation should mandate the tools to exist and be usable by carers without govt or commerical entities needing to know anything at all about the people involved.

                          Carers need to be able to delegate their restriction requirements to platforms, and trust that they work. They do NOT need to delegate their decision to apply a restriction. That stays between them and the person in their care.

                          I say we should not hand over duty of care to other agencies 2/2

                          1 Reply Last reply
                          0
                          • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

                            And to those that say that anonymity (or rather pseudonymity) can be implemented with zero knowledge proofs — yes. But that’s not what is being used in currently preferred age/identity verification „solutions“ which tend to be centralised, commercial offerings.

                            2/2

                            argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                            argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                            argv_minus_one@mastodon.sdf.org
                            wrote sidst redigeret af
                            #42

                            @jwildeboer

                            There is no such thing as zero-knowledge proof. Such schemes merely change which big government/business gets the knowledge.

                            See, for example, the European Digital Identity Wallet (EUDIW). The EU government doesn't get the knowledge of which websites you're using…but the app requires the use of a Google-approved phone, so Google gets the knowledge.

                            Anonymity, and therefore privacy and freedom of speech, is fundamentally incompatible with age verification. Full stop.

                            jwildeboer@social.wildeboer.netJ 1 Reply Last reply
                            0
                            • argv_minus_one@mastodon.sdf.orgA argv_minus_one@mastodon.sdf.org

                              @jwildeboer

                              There is no such thing as zero-knowledge proof. Such schemes merely change which big government/business gets the knowledge.

                              See, for example, the European Digital Identity Wallet (EUDIW). The EU government doesn't get the knowledge of which websites you're using…but the app requires the use of a Google-approved phone, so Google gets the knowledge.

                              Anonymity, and therefore privacy and freedom of speech, is fundamentally incompatible with age verification. Full stop.

                              jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                              jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                              jwildeboer@social.wildeboer.net
                              wrote sidst redigeret af
                              #43

                              @argv_minus_one Yep. That's my point.

                              1 Reply Last reply
                              0
                              • jwcph@helvede.netJ jwcph@helvede.net

                                @kasperd @kramse @jwildeboer @michael That's a lot of words just to say "I don't think we should hold the platforms making billions on endangering & harming our children responsible"...

                                argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                                argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
                                argv_minus_one@mastodon.sdf.org
                                wrote sidst redigeret af
                                #44

                                @jwcph

                                Is the Fediverse “making billions on endangering & harming our children”?

                                No, of course not. The vast majority of Fedi sites aren't making money at all, let alone billions. They're paid for by some volunteer's day job and a trickle of donations.

                                So why are Fedi sites to be forced to either conjure billions out of thin air to pay for age verification, or shut down entirely?

                                @kasperd @kramse @jwildeboer @michael

                                kramse@helvede.netK 1 Reply Last reply
                                0
                                • argv_minus_one@mastodon.sdf.orgA argv_minus_one@mastodon.sdf.org

                                  @jwcph

                                  Is the Fediverse “making billions on endangering & harming our children”?

                                  No, of course not. The vast majority of Fedi sites aren't making money at all, let alone billions. They're paid for by some volunteer's day job and a trickle of donations.

                                  So why are Fedi sites to be forced to either conjure billions out of thin air to pay for age verification, or shut down entirely?

                                  @kasperd @kramse @jwildeboer @michael

                                  kramse@helvede.netK This user is from outside of this forum
                                  kramse@helvede.netK This user is from outside of this forum
                                  kramse@helvede.net
                                  wrote sidst redigeret af
                                  #45

                                  @argv_minus_one @jwcph @kasperd @jwildeboer @michael

                                  pretty sure what was meant was Facebook et al, which are the places where abuse happens

                                  1 Reply Last reply
                                  0
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Har du ikke en konto? Tilmeld

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper