7 ms·
I quite like the EU approach. It's a decent spec. Most countries already have digital apps to verify identity, like Denmark's MitID (https://www.mitid.dk/en-gb/
by dreadnip 6mo ago
I quite like the EU approach. It's a decent spec. Most countries already have digital apps to verify identity, like Denmark's MitID (https://www.mitid.dk/en-gb/get-started-with-mitid/ https://www.mitid.dk/en-gb/get-started-with-mitid/). These could be expanded to fully EUDI compliant wallets and deliver encrypted proof-of-age without exposing any other identity.
For example a gambling site could require MitID auth, but only request proof-of-age and nothing else. You can see in the app which information is being requested, like with OAuth.
- y-curious 6mo agoI don’t mean to be as aggressive as this sounds but the frogs probably liked the increasingly warm water too until it started boiling. How many steps between MitID and a fork that is used to enforce extreme censorship?
- boesboes 6mo agoEverything is a slippery slope if you tilt & twist it enough...
- snackbroken 6mo agoThis particular slope has consistently had people pratfalling over and over again for hundreds of years.
- dreadnip 6mo agoMitID is run by the government. How would anyone fork it? Any service implementing MitID auth can verify through signatures that they're connecting to the official service. I don't want my kids to have access to gambling websites like Stake, but I also want to keep my digital identity anonymous. The eIDAS is a solution that achieves both of these goals. If you can choose between the discord shitshow with a face scan, or a digital encrypted proof-of-age in a 2FA app you already use, issues and verified only by the government of your country (who have all your personal details anyway), what would you choose?
- izacus 6mo agoHaving the government be the issuer and verifier of personal IDs is hardly a "boiling frog" situation anywhere in the world.
- SiempreViernes 6mo ago> During the 19th century, several experiments were performed to observe the reaction of frogs to slowly heated water. In 1869, while doing experiments searching for the location of the soul, German physiologist Friedrich Goltz demonstrated that a frog that has had its brain removed will remain in slowly heated water, but an intact frog attempted to escape the water when it reached 25 °C. From wikipedia.
- snackbroken 6mo agoIf there's no information provided beyond proof-of-age, what's stopping my friend's 18 year old brother from lending his ID to every 14 year old at school? IRL that's negated by the liquor store clerk looking at the kid who is obviously underage and seeing that his face doesn't match the borrowed card he just nervously presented.
- Mashimo 6mo ago> what's stopping my friend's 18 year old brother from lending his ID to every 14 year old at school? MitID is 2fa. You log in with username, then you have to open the app, enter password or scan biometric, then scan the QR code of the screen* and you are logged in. He would need to be next to you every time you log in. I think that is too high friction to make it feasible on large scale. * Assuming you open the website on the Desktop, and MitID on phone. If both on phone, skip this step.
- snackbroken 6mo ago> He would need to be next to you every time you log in. Or you can just text him a screenshot of the QR code. You could probably even automate this.
- Mashimo 6mo agoNo, the QR code is changing every couple of seconds. ~Maybe~ you can video call, but again it's adding so much friction. Nothing is 100% secure.
- snackbroken 6mo agoThe automated attack setup I'm envisioning is something like: 18 year old buys a cheapo laptop + phone and connects the two over ADB or some purpose built automation app (think appium). 18 year old puts the phone on a tripod pointed at the laptop screen. 14 year olds at school pay $10 a year for use of the service and install a browser extension that forwards the QR codes from whichever service they wanna use to the 18 year old's computer. Changing every couple of seconds is not an issue here, they all live in the same city and have <10ms ping. The only high friction part of this is that someone needs to write the software for it, but that doesn't seem like all that difficult of a project and open source solutions are likely to appear within weeks of social media requiring it. If there really is no information shared with the other party beyond "yup, user is over the age of maturity" you could even run this as a free public TOR service without fear of ever getting caught.
- pjc50 6mo agoGambling sites already have payment information, which should include real names! (no, you should not be allowed to do non-KYC gambling, that's just money laundering)
- Mashimo 6mo agoBut how do you go from real name to age verification?
- ben_w 6mo agoI think it's more that proof of identity from the union of {payment information, KYC} also includes both of age verification and name, not that name leads to age.
- Mashimo 6mo agoAre the payment providers sending the age to the gamling site?
- ben_w 6mo ago> union of {payment information, KYC} As in, if you're not matching the payment info to your customer info, you (which may be the company or the government passing the laws the company is following just fine) did it wrong. Because, as pjc50 wrote, failing to do that is an obvious exploit for money laundering.
- Mashimo 6mo agoSorry, I don't get it. If I'm underage, but already have a payment card, the identity of the card matches my name. That is why dreadnip suggested the MitID approach.
- ben_w 6mo ago> If I'm underage, but already have a payment card, the identity of the card matches my name. And if a gambling site stops there and goes "LGTM", it's not the "union of {payment information, KYC}". Union, as in combination of both. KYC, as in "Know Your Customer". Looks like MitID is a thing that would be one way to do KYC? But I've only just heard of it, so belief is weakly held.