Rendered at 16:52:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
big85 19 hours ago [-]
All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
yodsanklai 16 hours ago [-]
> All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason ...
Maybe I'm naive, but I think there's no deeper motivation. There are activists and politicians who really believe this is a cause worth fighting for.
inigyou 6 hours ago [-]
Some people want this. Other people want mass surveillance. Conveniently, they are aligned! The mass surveillance people will shoot down any version of age verification that doesn't also allow mass surveillance.
1vuio0pswjnm7 3 hours ago [-]
"Maybe I'm naive, but I think there's no deeper motivation."
Maybe you are not naive. Maybe you are correct
This "real reason for age verification" trope might be just another braindead meme or conspiracy theory
No evidence has been presented to support what these commenters are suggesting
It stands to reeason that anyone who is truly concerned about "connect[ing] real-life identifiers to online activity" would be distancing themselves from using corporate-controlled mobile operating systems like Android or iOS, as opposed to thinking, something like, "I've got a good thing going here with Android and/or iOS and age verification is going to ruin it"
skeptic_ai 16 hours ago [-]
Maybe we should start by tracking their every movement to see if they enjoy
m132 16 hours ago [-]
Of course they won't. That's why there's precisely an exemption for government personnel in Chat Control.
Not just exempting themselves, but actively building and deploying end-to-end encrypted chat apps for gov only use with (non)retention and (un)transparancy fully under their own control. Tbf, we're still waiting for Von Der Leyen's SMS's, and that was not even on such an app. Some can just ignore the law without repercussions.
Gud 8 hours ago [-]
Already happening.
squigz 6 hours ago [-]
It can be both, and there can be both individual and systemic motivations involved.
preg_match 1 hours ago [-]
[dead]
zb3 17 hours ago [-]
> The real reason, of course, is to force people to connect strong real-life identifiers to online activity.
This is worse than that, this paves a way for corporations to shove anti-user crap (adware, spyware, "sideloading" restrictions etc) to devices that are mandatory for you.. and in a way you can't fight it, because now government is protecting that crap without even realizing it.
It's one thing that I can't install a custom OS on my credit card.. but it's a different thing when that device is actively connected to the network, sending my data to some US company, prevents me from removing bloatware / installing my own software.. and on top of that displays ads.
inigyou 5 hours ago [-]
Parental controls don't exist. Not ones that actually work. That's why governments want to do something about it in the first place.
hellojesus 2 hours ago [-]
I'll take the bait.
Can't you just enroll your kid's devices in your home corporate and leverage MDM to force the network to call through your proxy, which denies or downgrades all ECH and then can actively filter to an allowlist or screen the material through your personal or contracted LLM?
This seems relatively solved to me.
jimmydorry 44 minutes ago [-]
The average Joe wouldn't know where to begin in setting that up. That solution is far from solving the problem.
inigyou 27 minutes ago [-]
Is this sarcasm?
hellojesus 4 minutes ago [-]
I was recommended by my psychiatrist to go get tested for autism recently. I suppose I should take that more seriously than I first did...
preg_match 1 hours ago [-]
The simplest parental control is just not giving your kid unrestricted internet access. It’s both cheaper and easier than the status quo.
I’m sorry, but if you don’t have a home computer in your living room for your kids homework, you haven’t put in any effort and I no longer care. Ideally nobody, anywhere, should care. You have to take actual steps. Very basic, easy steps.
Think about what you need technology for. To reach your kid, to do their homework. Okay. Now do you require 24/7 internet access on an arbitrary device for that? No. You can go to Walmart today and pick up a 20 dollar burner phone. But you didn’t, right? So do that first, analyze the landscape, and then I think there can be a conversation to be had.
Demanding a conversation or worse, a law, when the most basic steps have not been taken is frankly disrespectful. That’s how I view it, it’s a time wasting mechanism.
docjay 5 hours ago [-]
What doesn’t work for the ones that you’re aware of?
firesteelrain 14 hours ago [-]
PH endorses OS level controls though
burnt-resistor 6 hours ago [-]
Yep. This is billionaire-led corruption of governments globally to buy legislation that takes away our rights. It benefits data brokers, intelligence agencies, and police.
toasty228 5 hours ago [-]
> when parental controls already exist
The same parents who give smartphones to toddlers to keep them quiet? Good luck...
jmyeet 18 hours ago [-]
That's a completely unhelpful, overly simplistic straw man argument.
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
akersten 18 hours ago [-]
What's simplistic and unhelpful is falling for the narrative that infinite scroll, boobies, and algorithmic feeds are somehow more harmful than ubiquitous government surveillance of the most powerful communication tool on earth. The Internet, more or less, has been around 30+ years and the Something awful and 4chan generations are now in charge. We're not much worse off. The Internet is actually way tamer these days than it used to be.
We can all agree that yeah sure this social media stuff isn't great, but that's the whole point of freedom. Fast food isn't great either but lawmakers aren't pushing for a junk food attestation framework to make sure you don't consume it more than twice a week. In other words, your best interest is not interesting to them at all. They are happy that you think it is somehow self evident that we should subject ourselves to undue surveillance through!
So, wonder why they're pushing for this so hard. I'll take the brainrot if it means criticism and ideas can spread without permanently being associated with a trackable, unchanging identity.
SecretDreams 18 hours ago [-]
Don't know about boobies, but I would guess META/other infinite scroll products are this generation's cigarettes in terms of long term harm and we do a severe disservice to all young people that are exposed to this product. Moreover, asking parents to intervene is obviously not going to work because they, themselves, have been partially ruined by it and lack the critical thinking required to intervene and the prowess to execute. Same reason why we needed government to intervene for cigarettes.
I am not endorsing removing all anonymity from being online, but continuing the status quo with social media is a non starter for humanity. So tell me how we can help kids not get ruined by the internet without a mechanism specifically identifying that they're online in the first place?
0x000xca0xfe 18 hours ago [-]
Then the solution could be just like the solution to tobacco addiction: tax social media companies HARD, tax all advertising on social media 10x, 20x, or ban advertising on/for social media outright, ban advertising of kids products, ban showing use of social media in movies not rated 18, ... the problem will vanish just like cigarettes.
But no, that's not what governments are doing. They want control and surveillance.
matheusmoreira 17 hours ago [-]
Taxing or banning advertising alone would fix literally everything that is wrong with the web.
jryle70 16 hours ago [-]
Do you know what happen when advertising is banned? It would go underground -- product placement, contest, merchandises, and so on. Advertising existed as soon as commerce became a thing, probably thousand years ago. It can't be banned. I wouldn't vote for that.
Regulation, on the other hand, is fine. How? I don't know.
Sure it can. I don't see how being old makes it immune.
jimmygrapes 15 hours ago [-]
It'd be tough to phrase it right. Imagine that The Ones Who Ban Things decide to write something interpretable as essentially "nobody is allowed to inform others about things". The process of distilling any ad banning law into applicable testing of that law would be pretty scary to me
kilburn 12 hours ago [-]
Other legistlation plays a similar game:
- Slandering laws set a limit for what you can say about others
- Copyright laws set a limit on what you can share with others under which circumstances
Both those things seem similarly complicated to implement and yet we have them.
account42 5 hours ago [-]
You're saying that as if we don't already have all these.
akoboldfrying 16 hours ago [-]
Taxing may be a good way to restore balance. Banning means goodbye online news, Google Search, Gmail, YouTube, Maps, Translate, ad-supported games, etc. -- basically everything we've become accustomed to having for free will want a monthly subscription.
account42 5 hours ago [-]
> Banning means goodbye online news, Google Search, Gmail, YouTube, Maps, Translate, ad-supported games, etc.
Good.
frm88 10 hours ago [-]
This is the most sensible solution to this problem I have read on HN in the 2 years I've been here. Think of the positive effects taxation would have: no whack-a-mole for every loophole the industry will find. No single fines after costly court battles that are basically pocket change for Zuckerberg et al. Adherence to polluter-pays-priciple. Make it so that if they stop advertising, the tax expires. Use the tax money for better infrastructue. Make the tax progressive - the more ads, the higher the tax.
Added benefit: even adults will be less exposed to addictive material.
What would be the cons of this?
docjay 4 hours ago [-]
You get robbed and raped at the local park, broken bones riding a bike, permanent disability playing a sport, drown when swimming, disappear on a hike, overdose at a party, “become violent” playing video games, join a cult at a rock concert, rot your brain watching TV, eating disorders from ballet and gymnastics, traumatic brain injury from a trampoline, choke on a marble, fall when rock climbing, crash your car, get Lyme disease camping, get skin cancer playing outside, develop body dysmorphia playing with a Barbie, socially isolated without Facebook, socially dysfunctional with it, and join a gang if you have nothing else to do.
Everything, from “anything” to “literally nothing”, has been marched up on stage as the latest thing that’s a danger to children. All of it is true. Existing is dangerous, and that cannot be legislated away. Parents are supposed to be preparing their children for the dangers that life brings with it, not grinding down the tips of forks.
Having a healthy fear of skateboarding saved more broken bones than knee pads, so maybe parents should help their children understand that their peer isn’t as cool as they look on Instagram… or they get bombarded with it when they pass the minimum Facebook age and we’re back here in a few years raising the social media age to 35.
akersten 17 hours ago [-]
> I would guess
It's going to take a lot more evidence to get me anywhere near consideration that this is a trade worth making. Again, we know that fast food can be attributed to hundreds of thousands of early deaths per anum, but we regulate that not at all. In fact it's sadly a staple of the average kids diet.
Passing laws out of fear is not how any competent legislature should operate.
mindslight 16 hours ago [-]
> continuing the status quo with social media is a non starter for humanity. So tell me how we can help kids not get ruined by the internet without a mechanism specifically identifying that they're online
What if I told you it's very simple? We work at banning the harmful dynamics of corporate social media for everyone [0], rather than beating around the bush about kids. In fact, trying to avoid this is exactly why Faceboot et al are lobbying for this age verification crap in the first place - to escape the one tiny avenue of liability that has managed to exist, so they can keep kicking the can down the road.
Given how wholly top-down these proposals all are, frankly they would be better off being referred to as "give control of what your kids can see to the judgement of corporate attorneys.
[0] antitrust enforcement would go a long way here. Faceboot operates on online hosting service, so they should be prohibited from anticompetitively tying the client software used to access it (which necessarily includes "the algorithm").
dgroshev 17 hours ago [-]
Algorithmic scroll is factually more harmful, regardless of the amount of harm as long as it's non-zero, because it does affect people. Surveillance on its own doesn't. It just doesn't, everything that you can think of in response is not solely or even significantly caused by surveillance.
Instead, limiting surveillance (which in this case is only linked to the issue at hand with what's explicitly a conspiracy theory, so the link is quite tenuous) was originally meant to limit the government's powers as a form of control over the government. Control over the government is just a part of the Enlightenment project of societies being able to shape their destinies equitably, which includes shaping political arrangements.
Americans have completely lost the ability to shape their political system (when was the last constitutional amendment passed again?), so instead the discourse turned to fetishising particular tools that might help, but were never the point of having freedom. This is a fallacy.
There are straightforward ways to have age verification without descending into a dictatorship. To use an analogy, most European countries have mandatory IDs, some even have digital IDs; many of those counties are freer than the US.
Freedom is being able to stop kids from accessing pornhub without fearing a dictatorship because you can just prevent the dictatorship through a million other means. Freedom is not paralysing the political system as technology and progress (and multi-billion dollar megacorporations) march on.
Otherwise societies just get superficial "freedoms" (like using slurs in public spaces because "free speech") while their governments, say, run a paramilitary murdering political opponents on the street.
SoftTalker 16 hours ago [-]
"Boobies" really understates what is available virtually unrestricted on Pornhub and similar sites. If "boobies" were the extent of it, far fewer people would be worried about it.
jolmg 15 hours ago [-]
On restricting, I really think that's the responsibility of parents. I think the problem here is that Android and iOS don't empower their users (parents) to implement proper parental controls. I imagine apps don't get the access and maybe the parental controls implemented by the OS don't suffice? Maybe because Android and iOS benefit from these kinds of legislation that cement their duopoly.
SoftTalker 14 hours ago [-]
I agree that none of the current user platforms, i.e. Android, iOS, nor desktop, have adequate parental controls that are easy to use. Parental controls are important but that's not enough. We expect parents to not buy liquor for their kids, and make reasonable efforts to prevent their kids from obtaining it. But we also expect liquor stores to not sell liquor to kids. We should likewise expect that internet content platforms do not deliver inappropriate content to kids.
imtringued 10 hours ago [-]
Pornhub is incredibly restrictive about what can be uploaded and about identifying who is uploading the videos and is now also demanding proof of consent from the performers (presumably to avoid revenge porn).
If one of the most compliant actors is already "virtually unrestricted" then you just want to censor things you don't like and the censorship of porn is just a pretense for the things you actually want to censor.
happymellon 11 hours ago [-]
Based upon this sentiment, it's already too late as 2Girls1Cup already existed and has done it's damage to the current generation who are obviously deviants!
How can we even trust these lawmakers when Blue Waffles, Tub Girl and Goatsee already existed??!
Unless it hasn't. And while it's grosser than finding a copy of Readers Wives in the park, the "think of the children" angle is overhyped.
jolmg 18 hours ago [-]
> We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos.
These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc. Perfectly privacy preserving. You have no such guarantee when you upload government IDs to a server.
I don't think anyone here minds restricting access, but that doesn't require completely destroying ownership rights over our own devices nor internet and device privacy.
All that really needs to be done is for servers to publish what type of content they show from a parental perspective in a machine-readable format and for devices to have parental controls that only allow access to servers that publish such info and which content is allowed by the parental settings.
This should be even more effective than solutions requiring uploading IDs since there's still going to be servers out there in other jurisdictions that simply don't care for such things.
audunw 17 hours ago [-]
> You have no such guarantee when you upload government IDs to a server.
The problem is that so many people here look at this purely from a USA perspective.
An age check in many European requires no uploading of any ID. It’s an API call toward an ID service, it will tell you which data the service gets access to, and there’s strict regulations and liability around data retention.
I’m not concerned about the government. If they become authoritarian enough to worry, they will impose far tighter surveillance anyway. What we have now is the naive idea that just by not doing ID check, government surveillance is a solved problem in the free democratic world. It’s not. Avoiding ID checks just makes the problem worse because it makes the regular person complacent. The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked. Requiring audits of large corporations. Solutions that give corporations access to only the data they absolutely need and nothing else (the lack of such things is how we end up by uploading whole ID documents)
jolmg 17 hours ago [-]
> The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked.
We can't get perfect privacy so we should normalize not having any? Leave it to the government we're distrusting to handle our privacy?
> If they become authoritarian enough to worry, they will impose far tighter surveillance anyway.
What is this logic? Let's not worry about creeping there because if they want it they'll force it? That's not how it works. Getting to a surveillance state needs acceptance. To get that, rather than dropping people in boiling water, you slowly heat the pot, which is what this is.
dgroshev 17 hours ago [-]
Just a few decades years ago, everyone's names and phones in the US were freely available to anyone with a phone book. Communications were done in the clear, either via letters (hardly tamper-proof), or via phone (that anyone with access could tap).
Did every American live in a "surveillance state" back then?
pibaker 13 hours ago [-]
Bad analogy. A phone book tells you nothing about who you are talking to or what you are talking about over the phone. Most free countries don't let law enforcement read letters without a warrant. And even in authoritarian states the police couldn't wiretap everyone or read every letter. The volume was simply too massive for any manual operation.
Digitalization and now AI technology changes this drastically because it makes it drastically cheaper to record and flag human communications.
jolmg 17 hours ago [-]
What could be tracked from phones back then compared to now is completely different. Phones are basically only called "phones" for historical reasons.
dgroshev 16 hours ago [-]
So what? Some things are exceptionally hard to track now (like e2ee messages) that were trivial to track back then.
Every remote communication could only be had in the clear. Everyone was fine with that. Was the US in the 80s a surveillance state?
jolmg 16 hours ago [-]
Back then there was only the possibility of listening-in on particulars, and even then people did worry. They weren't fine with that. That's why there's wiretapping laws enacted in the 80s.
Today, and as things continue to progress with speech-recognition, LLMs, video recognition, etc. surveillance can be automated. It's looking conceivable to be able to process all communication population-wide in real-time. That would have been unimaginable back then.
Now, texts and calls today are only a small role of phones. For many people, it's their primary general computing device. It's how they interact with the world. It contains their entire digital life.
Couldn't look at your photo reels and videos, and diary, and every purchase you've ever made, every opinion you've ever said on a public space, every community you've ever interacted with, every location you've ever been in down to the room, from wiretapping a phone in the 80s.
> Some things are exceptionally hard to track now (like e2ee messages) that were trivial to track back then.
Can be easier than back then if stuff like chat-control comes to pass, because now the message can be obtained, processed and stored indefinitely in an automated fashion for everybody at once. E2EE becomes security theater for the most part.
dgroshev 16 hours ago [-]
You just said it yourself: the perceived danger of overreach was averted through new laws and control over what the government is doing.
If citizens still have a capacity to restrict the government via (enforced) laws, it doesn't matter much that the communications are in the clear. You can layer something on top just to be sure, but the foundation is laws and a functioning political system.
If there's no functioning political system, the government will just do whatever, like buying the same data they ostensibly can't collect from commercial providers (who weren't restricted from collecting it because there's no US GDPR).
If a country has a functioning political system, it can just do things like ban gun ownership, introduce mandatory IDs, publish everyone's yearly income, or criminalise calling other people slurs in public and not become an uncontrollable dictatorship. If it doesn't, corruption and democratic backsliding will happen regardless. Hyper-focusing on a few tools and superficial traits of a particular system in a particular moment is myopic.
jolmg 15 hours ago [-]
> You just said it yourself: the perceived danger of overreach was averted through new laws and control over what the government is doing. If citizens still have a capacity to restrict the government via (enforced) laws
Restricting the government via laws... The government implements the laws. Trying to restrict the government via laws is mostly just asking "pretty-please don't screw us over." They're not going to make a difference to a corrupt government. Government corruption will become more enticing too because of the added concentration of power it would have. How have laws been working for restricting Trump? He's shown how easily they can be sidestepped and manipulated.
Also, back then implementing end-to-end encryption of all calls wasn't feasible. That would have been the preferred option. It's feasible now. We have it. Why rely on something as fallible as government-restricting laws when we have better options?
It's better for power to be decentralized, as it is with every device owner having sole access to their own devices. As well as being able to communicate anonymously, which is huge for matters of free-speech and democracy.
dgroshev 15 hours ago [-]
Indeed, Trump is a great example of democratic backsliding completely unfettered by "freedoms" often mistaken for the actual freedom. The way forward is being able to change things or regaining this ability if it's lost, not trying to carve out some bit that's not under the government's control yet. That's just a form of escapism.
fyredge 12 hours ago [-]
There is a malaise permeating modern culture, where social action does not enter the mind at all, possibly because it does not provide instant results. Collective action and organising local communities has always been the solution to social ills. It's why I'm looking forward to the progressives in US, they seem to be organising themselves quite well.
knollimar 18 hours ago [-]
do parents not control routers and cell plans? I feel like it would be easy to look here for header based solutions. They probably exist tbh. Then just ban your kid from VPNs.
17 hours ago [-]
monk_grilla 18 hours ago [-]
Any time I've been in an age-restricted venue here in Australia they have taken a picture of me and my ID at the door.
hellojesus 2 hours ago [-]
Even so, they likely aren't recording everything your eyes see and for how long they linger. They likely aren't recording your entire traversal through the venue, what you do, what you say, what times you go there, from where you connect, etc. Simply being at a public place is one data point. A full history of your entire interaction is a magnitude different.
1 hours ago [-]
17 hours ago [-]
txrx0000 17 hours ago [-]
> So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed.
The market failure to provide an adequate solution wasn't natural. It was engineered by the tech companies and you are playing right into their hands. There is still a way to fix this from the root with software antitrust: force hardware vendors to ship their devices without an operating system.
Here's a more detailed explanation in a past comment about how the problem came to be in the first place, and why software antitrust can solve it:
> I personally believe that the easiest thign to attack is advertising to minors.
Well then, let's regulate this instead? Advertising companies already make a pretty good guess about a person's age. It doesn't require 3rd parties and age verification.
But we won't — this isn't why identity checks are getting lobbied.
> I believe we should shift that liability to advertising.
I am confused. Are you saying that advertising companies should handle these identity checks? So let's just hand out a unique identifier to the companies who have monetary interest in this? Surely this will end well.
matheusmoreira 17 hours ago [-]
> So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed.
Absolute bullshit. This "unfettered access" is the whole reason why I am who I am today, why I am here. Not only did it not fail, it's in fact so successful it threatens the powers that be, and that's the real reason why they want to ban it.
> I personally believe that the easiest thign to attack is advertising to minors.
Now this I agree with. I would be even more radical. It's not just advertising "to minors", all advertising needs to get banned straight up. Advertising is mind rape. Ban it and all the problems with the web will be fixed literally overnight, including the problems "mandated hardware attestation" aims to solve. There is no need whatsoever for this attestation nonsense.
xg15 18 hours ago [-]
What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors.
It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
jmyeet 18 hours ago [-]
This is the slippery slope fallacy and people in tech seem to love this argument. And you can argue in whichever direction you want with it.
For example, "unfettered Internet access is just a series of tubes (shout out to Ted Stevens for that one) for pedophiles to rape your children." So now what? Is it your hyperbole against mine?
The problem is that people are operating under a myth that they have anonymity. You don't. You're one subpoena away from being unmasked online and individuals can do it (eg [1]). When governments do it, they can do it in secret. National Security Letters, pen registers, FISA warrants, etc.
So the idea that "age verification is the first step to a more comprehensive" is flawed in both logical construction (being a fallacy) and that ship has already sailed.
But in this case, the slipping just happened. This thread is about how an app that will be required for using a vast fraction of all websites will require hardware attestation and likely only run on closed, non-rooted mobile OSes. That's not a hypothetical scenario, it's literally what this thread is about.
throw-the-towel 16 hours ago [-]
Maybe it's reasonable to argue a slope is slippery if you've just seen someone lubricate it.
14 hours ago [-]
smallerize 17 hours ago [-]
We must do something.
This is something.
Therefore, we must do this.
protocolture 18 hours ago [-]
>So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed.
How has it failed? Whats the measure of a successful freedom vs an unsuccessful one.
>The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
No its the positive case for action that remains to be justified.
catlikesshrimp 18 hours ago [-]
>> "We're creating gambling addicts (which is arguably the most harmful form of addiction)"
---
I will need a source, because "arguably" is a very broad umbrella.
"Arguably" heroin addiction is the most harmful addiction because heroin is the most addictive substance, clouds judgement and drives the addict to all manners of sociopathic behaviour (not only theft or prostitition)
jmyeet 17 hours ago [-]
One big difference is that heroin is mostly illegal or, if not outright illegal, decriminalized for personal use. Gambling is legal in most places, can be advertised quite freely and restrictions can be easily circumvented with crypto. Crypto casinos have little to no age verification and typically operate extrajudicially (from the victim). Gambling addiction has a high outcome of suicide and tends to leave financial ruin affecting not just that person but their entire family.
Heroin addiction was largely created by the criminialization of cannabis (the first so-called War on Drugs under Nixon) as a tool to persecute black people and war protesters and the overprescription of opioids (eg the Sacklers/Purdue).
catlikesshrimp 15 hours ago [-]
That last sentence is neither here not there. I don't think gambling is good; I would have it gone from the internet and reserved to casinos. There is no MORAL justification to push for government control so gambling online can be legal.
jimbob45 18 hours ago [-]
Fentanyl, no?
catlikesshrimp 15 hours ago [-]
Fentanyl is another opioid, like heroin; it also has a very high addictive potential. But, if I am not mistaken, the real problem with fentanyl is that dealers contaminate other drugs with fentanyl, which becomes lethal when not done correctly (and dealers aren't very responsible)
cindyllm 15 hours ago [-]
[dead]
thmryth 17 hours ago [-]
[flagged]
AuthAuth 14 hours ago [-]
There should be real life identifiers connecting to online activity. Why should online actions be untraceable? That only empowers bad actors.
CamperBob2 14 hours ago [-]
I don't see your real name on your user page, unless your parents named you AuthAuth.
bulbar 13 hours ago [-]
Bad actors will stay untraceable.
What specific generalized problem would you like to be solved that you advocate for such a generalized solution?
stuaxo 14 hours ago [-]
Goodbye whistleblowing.
afandian 19 hours ago [-]
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
txrx0000 17 hours ago [-]
This is the correct intuition. The problem can be solved with antitrust by forcing hardware vendors to ship their devices without an operating system. Then the market will deliver the parenting solutions that don't require mass surveillance. We're currently being blocked from doing so by anti-competitive measures.
The EU way is to think these things are “free” and then act surprised by the inevitable consequences five years later when it is irreversible.
Our AI gods cannot save us soon enough.
afandian 19 hours ago [-]
What are the "AI gods" going to do in this scenario?
AI is about many things, but a big factor is enclosure.
toasty228 5 hours ago [-]
They already regulate the amount of rain water you can collect, or how much water you can take from your own well, or how many solar panels you're allowed to use
You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up
wmf 17 hours ago [-]
Their solution is to "force open" iOS and Android through the DMA, not to create competition which they know won't work.
petcat 19 hours ago [-]
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
realusername 19 hours ago [-]
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
inigyou 5 hours ago [-]
What do you expect - the EU to centrally plan a phone OS? They are capitalist with regulations, you know, not communist. Someone has to actually make one themselves.
Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share.
petcat 4 hours ago [-]
> are already European, like MNT, and GrapheneOS
GrapheneOS is Canadian.
inigyou 4 hours ago [-]
After France drove them away, right?
realusername 5 hours ago [-]
What do I expect? Mandating open bootloaders by law, banning device attestation and applying existing antitrust legislation.
Then if they could give a few millions to some open source communities, that could be the cherry on top
inigyou 4 hours ago [-]
Now that would be pretty good. I thought there was already an unlockable bootloader mandate but it seems I was mistaken. Most phone makers openly violate GPL and don't get punished, too.
afandian 18 hours ago [-]
Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale.
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
varispeed 18 hours ago [-]
Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
tzs 18 hours ago [-]
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
_jackdk_ 18 hours ago [-]
And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
matheusmoreira 17 hours ago [-]
> Most analysts expect
Total bullshit.
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
izacus 17 hours ago [-]
You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use.
We use that approach in several other industries.
But.... that requires work beyond just complaining.
imtringued 8 hours ago [-]
>But.... that requires work beyond just complaining.
So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to.
The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care.
For the people who care, it's not a matter of work, because they don't operate the platform.
matheusmoreira 16 hours ago [-]
> You can of course create an independent attestation database at any time
Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
Come on now.
> minimum security requirements for digital ID use
Also known as "the user has no control over the device".
Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.
> We use that approach in several other industries.
Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
izacus 16 hours ago [-]
> Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
That sounds mostly like copium just to motivate your complete inaction.
Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU.
But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.
matheusmoreira 15 hours ago [-]
> we're using similar approval processes across multiple industries to certify hardware
Why not tell us more about the requirements for hardware certification?
Seriously doubt it's anything but the usual war on general purpose computing.
Requirement #1, the computer runs the mandated surveillance software.
Requirement #2, the computer does not allow the user to run any software not approved by the government.
Requirement #3, the computer resists tampering so as to preserve the previous requirements.
izacus 14 hours ago [-]
> Why not tell us more about the requirements for hardware certification?
Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs).
But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment.
matheusmoreira 14 hours ago [-]
> cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM
So it must be secure against the user, as expected.
Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape.
> But sure, it's a all an evil conspiracy against general purpose computing.
You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this.
izacus 14 hours ago [-]
Yes, that's what a TPM or smart card chip in your ID/Passport does.
Prevents tampering even by the "user".
I have advocated nothing of the sort you're accusing me of. Please leave your strawman at home.
Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away.
matheusmoreira 12 hours ago [-]
> Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away.
It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you.
The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive.
It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online.
izacus 11 hours ago [-]
In most EU states you already need to provide ID to establish internet service, so what are you on about man?
imtringued 8 hours ago [-]
>Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux.
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
pembrook 16 hours ago [-]
I literally lol'd at the "Most analysts expect..." line.
Yea, most analysts didn't expect the cookie banner nightmare we're living in either.
To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse.
WhyNotHugo 20 hours ago [-]
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
Elfener 20 hours ago [-]
And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
zenoprax 17 hours ago [-]
> The project’s position is that hardware binding remains required
I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?
I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.
Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.
filleokus 17 hours ago [-]
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.
The key material must be DRM'ed, especially if some ZKP solution is used.
Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.
(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)
10polkoranin 16 hours ago [-]
Perhaps one could construct a bond-based system. It wouldn't help family collusion, but it would help limit people of age selling their authentication ability.
Say you have a public service and a platform site (social media, gambling, whatever), and the user does authentication in a way that anonymously proves to the platform that they're of age while revealing nothing else, and without revealing to the public service what platform they're accessing. But the protocol requires some expensive data (token that provides access to a bond account) which anybody MITMing the protocol can obtain.
Then if Alice tries to sell her age verification abilities to Bob, the protocol could be designed so either Alice learns the negotiated key and can snoop on everything Bob does, or she has to let Bob do a man-in-the-middle over a channel and lose the ability to observe what's going on after the first key exchange; and then Bob can acquire the token and make use of it at a later time.
This is very handwave-ish, but I don't think such a protocol would be impossible to design.
Under normal use, Alice has no reason to drain her own bond account. But if she's selling to an anonymous crowd who might use the token at any time (hence she can't trace the traitor), some troll is eventually going to do it.
matheusmoreira 17 hours ago [-]
> If you want to actually enforce age restrictions
I don't.
This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.
dwattttt 16 hours ago [-]
Do you also oppose drivers licensing, alcohol age limits? Those rely on a trusted ID managed by a government.
matheusmoreira 16 hours ago [-]
Not exactly a fan of those either, but they're much easier to tolerate because so far they aren't implementing a surveillance state straight out of a cyberpunk dystopia just to prevent kids from driving or drinking.
It's not like the car refuses to start if a dad tries to teach his kid how to drive.
imtringued 8 hours ago [-]
I have never been asked to show my ID ever in my entire life when buying alcohol.
The alcohol age limit equivalent would be to put the entire TPM + proprietary software infrastructure into the cash register, locking in a monopoly on what software can be used on cash registers. Not to mention, you now have to scan your ID, which then obviously gets recorded forever, allowing the government to track your alcohol consumption.
Yeah, I'm against that and I don't even drink alcohol, not even the alcohol I've bought myself as a gift to my parents.
zarzavat 16 hours ago [-]
Xkcd 538. Hardware attestation is not required because it's not sufficient, you need to plug all the other much easier ways to get around the system.
Firstly, you need to comprehensively ban VPNs, probably with some great firewall setup.
Secondly, you need to install CCTV in people's homes to make sure that nobody uses someone else's device to get around the system.
Then it's time for hardware attestation.
zb3 16 hours ago [-]
> I don't see how we can avoid the "trusted" hardware requirement.
While this is a good point, what's missing here is that this hardware doesn't have to have Google spyware and other bloatware installed. Yet with current design, this becomes mandatory.. security requirements are abused here to force unrelated software on my computer that I have to carry with me in order to participate in society.
This app should work on a dedicated device, something like a smartcard with e-ink display.. it would even be more secure because it would have less attack surface. Just like today I'm not complaining about not being able to install linux on my credit/SIM card, I'd not complain about that either. But locking down the whole OS on my smartphone is unacceptable.
afandian 19 hours ago [-]
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
big85 19 hours ago [-]
So much for the EU's mission to reduce e-waste.
teravor 19 hours ago [-]
note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
freefaler 14 hours ago [-]
Cory Doctorow had a very profound talk about it very long time ago (10+years).
As the internet become the place where people do a lot of things, no government (and especially no security services) will be able to keep themselves from trying to control it or at least monitor it. And with the new LLM features they can automatically do much more than before.
Human nature is a constant and when the government sees an easy way to enforce something, many more bureaucrats will try to do it.
buran77 19 hours ago [-]
> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
hellojesus 7 minutes ago [-]
I still contest that I should be able to solder together a basic computer in my garage and communicate with the internet so long as I follow the communication standards. There is never a reason to outlaw general purpose computing.
xg15 19 hours ago [-]
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
izacus 17 hours ago [-]
Most countries allow tapping your ID card to a reader device as well.
0xfedcafe 18 hours ago [-]
Here comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.
euroderf 2 hours ago [-]
How about a grand trade: Age verification for Corporation ownership verification.
- No more shell companies.
- Only humans may own shares.
- Public ownership registers.
Know thine enemy.
MetroWind 46 minutes ago [-]
What a shit show lmao.
Problem: corporations pushing harmful ads and arranging social media timeline in harmful ways to kids
Solution: restricting the individuals. Giving corporations more control. Giving people less choice.
Yeah makes sense.
PeterStuer 9 hours ago [-]
What is the authority of the "repository maintainer" in question? It feels descisions like these far outstrip the pure technical.
dumberquestions 14 hours ago [-]
I predict that teenagers with irresponsible parents will continue to use social media and online anonymity will get worse.
tzs 17 hours ago [-]
It should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability).
That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.
Here's the expected timeline.
The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.
In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.
matheusmoreira 17 hours ago [-]
> It should be noted that this app is temporary.
Don't believe that for a second. Nothing is so permanent as a temporary government program.
pembrook 16 hours ago [-]
The concept of an income tax was originally supposed to be temporary.
throw-the-towel 16 hours ago [-]
And passports too.
wbl 13 hours ago [-]
The hardware security module does not need to change to support tying to a credentials. I showed how to do this years ago and the theory was known long before. Its just that the EU is making self imposed barriers to doing this right.
matheusmoreira 17 hours ago [-]
There it is. That's what this "age verification" nonsense was all about. Predictably, the unceasing "think of the kids" rhetoric came down to THIS.
Absolute control over people's computers.
It's not your computer anymore, it's the government's.
ChrisArchitect 19 hours ago [-]
Related:
European "age verification" "app" forcing everyone to use Android or iOS
The article mentions "approved applications". What role, if any, do apps play in age verification if it's implemented in hardware?
Grimeton 6 hours ago [-]
X509 is all you need.
userbinator 19 hours ago [-]
I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...
More precisely tries to prevent, but there have been occasional articles about breaking TPMs here; and I suspect once they become a major obvious barrier to freedom, we're going to see a lot more attacks on them, and more successful ones too.
izacus 5 hours ago [-]
People have been trying to defeat them for years how.
Dig1t 16 hours ago [-]
What happens if some social media site hosted in another country becomes popular and refuses to implement these age verification measures? Is the EU going to create a great firewall like China and start blacklisting sites? Are they going to ban VPN’s too? Seems like a slippery slope could easily get extremely invasive and restrictive.
It does seem like an effort to connect all online activity to real-world identities.
hurfdurf 10 hours ago [-]
Is the EU going to create a great firewall like China and start blacklisting sites
"Like the Chinese firewall, this European internet would block off services that condone or support unlawful conduct from third party countries."
Sound familiar?
CommanderData 18 hours ago [-]
Someone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea.
State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
Calamity 12 hours ago [-]
Indeed, I truly don't understand how simply enabling parental controls onto mobile devices handed to kids which then gets advertised to each website/app that they use isn't sufficient.
You make it an opt-in feature to "self-broadcast" that this device is being used by a minor. Solves 99% of the use cases. And for the remaining 1% — the really determined teenager — they'd never be stopped by this anyway. They'd social enginneer their way to access somehow.
16 hours ago [-]
TacticalCoder 19 hours ago [-]
By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
phendrenad2 16 hours ago [-]
The downvoted comments here are very interesting, and it really shows a divide in beliefs here. I fear that there's no reconciling this, and in the end we'll need two internets: The EUternet and the USternet.
tavavex 12 hours ago [-]
The US is moving in the same general direction, even if they take slightly different measures. The universal tracking of everyone is something all these governments can suddenly agree on.
If after this is enacted the firewalls aren't perfect, the internet will probably instead splinter into the Westernet and the everywhere-else-net for the rest of the countries that are too disorganized or uncaring to join in on the fun, maybe with a few safe havens of something resembling the old web in between.
pembrook 16 hours ago [-]
This is the most mind blowingly stupid thing I've ever witnessed..and in slow motion...I'm just astonished that the EU is cheerfully walking themselves into destroying the freedoms of their own citizens without much of fight.
The most privacy-obsessed people on earth are now handing a detailed log to their entire digital lives over to a group of barely-elected 3rd party overlords as well as foreign companies and intelligence agencies (if you think this won't be instantly compromised, you're tremendously naive).
...AND at the same time this is cementing monopolies for foreign tech companies within Europe. A double whammy of self-harm.
There's something very bleak about couching this under the 90s-era "protect the children" narrative too, given ultimately most Europeans care so little about children that they've rapidly stopped giving birth to them and in many countries have outsourced all childcare to the state.
It's not even a believable cover story anymore.
It seems more like the European officials looked over at the Chinese Communist Party's authoritarian control over the internet and thought to themselves, "Wow, look how little push back they get to their policies online! I want to do big fancy projects with other peoples money and have no accountability or transparency too!"
SnipeOfficial 18 hours ago [-]
[flagged]
jocelyner 14 hours ago [-]
[dead]
phonkd 18 hours ago [-]
[dead]
83642736392 19 hours ago [-]
[flagged]
dijit 19 hours ago [-]
It's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU.
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
razor-thin 19 hours ago [-]
I suppose you have a lot of data backing this claim?
The head of the EU, Ursula von der Leyen, isn't known to be anti-EU.
dijit 19 hours ago [-]
No head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
mort96 18 hours ago [-]
A good way to prevent this anti-EU sentiment would've been to not go through with these obviously stupid ideas. Weird that the EU doesn't seem to realize?
Or do you think, maybe, that there's a deeper issue here and the problem isn't exclusive to just these anti-EU politicians you want to scapegoat?
dijit 18 hours ago [-]
I think rejecting proposals from MEPs on the grounds that "it's against EU interests" would be very undemocratic and fuel the very anti-EU sentiment that it would supposedly combat.
mort96 10 hours ago [-]
And approving this kind of regulation doesn't?
dijit 10 hours ago [-]
idk what kind of fascist you are, but a free society doesn’t stop talking about something because certain leaders don’t like it.
In order to get legislation you want (say: gay rights) you have to risk legislation you don’t like, for some, that would be gay rights too…
mort96 4 hours ago [-]
Some legislation is good, some legislation is bad. Legislation allowing gay people to be gay is good. Legislation enforcing hardware attestation from Google and Apple to access services is bad. These are facts, not opinions; I'm not a moral relativist.
dijit 1 hours ago [-]
Literally opinions.
mort96 1 hours ago [-]
Again, I don't subscribe to moral relativism. Some things are good, some things are bad.
dijit 1 hours ago [-]
you mean the things you think are good, are good.
And things that you think are bad, are bad.
Everyone feels this way about their things.
mort96 14 minutes ago [-]
No, I meant what I wrote. Some things are good, some things are bad. Some people are wrong.
There are plenty of subjective areas where people can disagree without being fundamentally bad people. These things are not those.
dijit 3 minutes ago [-]
I'm impressed that you know everything that's good and bad to be so resolute that you are the person who knows it all, it must be pretty incredible to be the one person on earth who has no doubts at all about what objective good and objective bad is. Maybe we should get you some place safe so we can have you judging humanities actions.
What's your position on military spending? Because if we don't spend then our countries get invaded (see: Ukraine) but if we do spend then we're taking money from starving families.. hrm..
I personally have a really hard time, since unfortunately I can empathise with the motivations of others, and everyone has a point, even if I don't agree with it.
The thing is, that I'm aware that everyone thinks they're the good guy, the hero, or the "necessary evil for the greater good", and I find it more interesting to understand why they think what they think is better than what I think.
The alternative means I've already factored the entire populations needs and circumstances, which, for my tiny meat brain which can only empathise with one person at a time is practically impossible.
How did you manage it?
Saline9515 11 hours ago [-]
EU parliamentaries don't initiate laws, and, during the "trilogue" with the EC and the Council, they don't hold the pen on the final version.
If any entity is "self-sabotaging", it's the European Commission. But it's not self-sabotage, it's simply yet another bureaucratic measure to assert power and control the population.
sajithdilshan 19 hours ago [-]
If it stick to its current trajectory it will implode in 10-20 years. France’s debt crisis will trigger Euro collapse and Germans would ditch Euro to not foot the bill for the French and the rest of the dominos would fall
throw-the-towel 15 hours ago [-]
The tragic thing is, European integration is really a beautiful idea; but it's now irreparably welded with this specific implementation of the EU. When the EU collapses, the European idea could well become collateral damage.
user00005 14 hours ago [-]
I searched this page for 'fascist', 'fascism', 'far left', and 'liberal' and there were no results.
A surprising little amount of criticism considering the rhetoric in any political right adjacent threads on this website. There are three mentions of 'trump'.
Saline9515 11 hours ago [-]
This is neither a far-left, far-right or centrist measure. It's a pure technocratic one, where the State and its minions believes optimize for control over the population, and matters like "privacy" or "resilience" don't appear in the cost function.
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
Maybe I'm naive, but I think there's no deeper motivation. There are activists and politicians who really believe this is a cause worth fighting for.
Maybe you are not naive. Maybe you are correct
This "real reason for age verification" trope might be just another braindead meme or conspiracy theory
No evidence has been presented to support what these commenters are suggesting
It stands to reeason that anyone who is truly concerned about "connect[ing] real-life identifiers to online activity" would be distancing themselves from using corporate-controlled mobile operating systems like Android or iOS, as opposed to thinking, something like, "I've got a good thing going here with Android and/or iOS and age verification is going to ruin it"
https://europeanpirates.eu/chatcontrol-eu-ministers-want-to-...
This is worse than that, this paves a way for corporations to shove anti-user crap (adware, spyware, "sideloading" restrictions etc) to devices that are mandatory for you.. and in a way you can't fight it, because now government is protecting that crap without even realizing it.
It's one thing that I can't install a custom OS on my credit card.. but it's a different thing when that device is actively connected to the network, sending my data to some US company, prevents me from removing bloatware / installing my own software.. and on top of that displays ads.
Can't you just enroll your kid's devices in your home corporate and leverage MDM to force the network to call through your proxy, which denies or downgrades all ECH and then can actively filter to an allowlist or screen the material through your personal or contracted LLM?
This seems relatively solved to me.
I’m sorry, but if you don’t have a home computer in your living room for your kids homework, you haven’t put in any effort and I no longer care. Ideally nobody, anywhere, should care. You have to take actual steps. Very basic, easy steps.
Think about what you need technology for. To reach your kid, to do their homework. Okay. Now do you require 24/7 internet access on an arbitrary device for that? No. You can go to Walmart today and pick up a 20 dollar burner phone. But you didn’t, right? So do that first, analyze the landscape, and then I think there can be a conversation to be had.
Demanding a conversation or worse, a law, when the most basic steps have not been taken is frankly disrespectful. That’s how I view it, it’s a time wasting mechanism.
The same parents who give smartphones to toddlers to keep them quiet? Good luck...
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
We can all agree that yeah sure this social media stuff isn't great, but that's the whole point of freedom. Fast food isn't great either but lawmakers aren't pushing for a junk food attestation framework to make sure you don't consume it more than twice a week. In other words, your best interest is not interesting to them at all. They are happy that you think it is somehow self evident that we should subject ourselves to undue surveillance through!
So, wonder why they're pushing for this so hard. I'll take the brainrot if it means criticism and ideas can spread without permanently being associated with a trackable, unchanging identity.
I am not endorsing removing all anonymity from being online, but continuing the status quo with social media is a non starter for humanity. So tell me how we can help kids not get ruined by the internet without a mechanism specifically identifying that they're online in the first place?
But no, that's not what governments are doing. They want control and surveillance.
Regulation, on the other hand, is fine. How? I don't know.
https://en.wikipedia.org/wiki/Cidade_Limpa
https://99percentinvisible.org/article/clean-city-law-secret...
Sure it can. I don't see how being old makes it immune.
- Slandering laws set a limit for what you can say about others
- Copyright laws set a limit on what you can share with others under which circumstances
Both those things seem similarly complicated to implement and yet we have them.
Good.
Added benefit: even adults will be less exposed to addictive material.
What would be the cons of this?
Everything, from “anything” to “literally nothing”, has been marched up on stage as the latest thing that’s a danger to children. All of it is true. Existing is dangerous, and that cannot be legislated away. Parents are supposed to be preparing their children for the dangers that life brings with it, not grinding down the tips of forks.
Having a healthy fear of skateboarding saved more broken bones than knee pads, so maybe parents should help their children understand that their peer isn’t as cool as they look on Instagram… or they get bombarded with it when they pass the minimum Facebook age and we’re back here in a few years raising the social media age to 35.
It's going to take a lot more evidence to get me anywhere near consideration that this is a trade worth making. Again, we know that fast food can be attributed to hundreds of thousands of early deaths per anum, but we regulate that not at all. In fact it's sadly a staple of the average kids diet.
Passing laws out of fear is not how any competent legislature should operate.
What if I told you it's very simple? We work at banning the harmful dynamics of corporate social media for everyone [0], rather than beating around the bush about kids. In fact, trying to avoid this is exactly why Faceboot et al are lobbying for this age verification crap in the first place - to escape the one tiny avenue of liability that has managed to exist, so they can keep kicking the can down the road.
Given how wholly top-down these proposals all are, frankly they would be better off being referred to as "give control of what your kids can see to the judgement of corporate attorneys.
[0] antitrust enforcement would go a long way here. Faceboot operates on online hosting service, so they should be prohibited from anticompetitively tying the client software used to access it (which necessarily includes "the algorithm").
Instead, limiting surveillance (which in this case is only linked to the issue at hand with what's explicitly a conspiracy theory, so the link is quite tenuous) was originally meant to limit the government's powers as a form of control over the government. Control over the government is just a part of the Enlightenment project of societies being able to shape their destinies equitably, which includes shaping political arrangements.
Americans have completely lost the ability to shape their political system (when was the last constitutional amendment passed again?), so instead the discourse turned to fetishising particular tools that might help, but were never the point of having freedom. This is a fallacy.
There are straightforward ways to have age verification without descending into a dictatorship. To use an analogy, most European countries have mandatory IDs, some even have digital IDs; many of those counties are freer than the US.
Freedom is being able to stop kids from accessing pornhub without fearing a dictatorship because you can just prevent the dictatorship through a million other means. Freedom is not paralysing the political system as technology and progress (and multi-billion dollar megacorporations) march on.
Otherwise societies just get superficial "freedoms" (like using slurs in public spaces because "free speech") while their governments, say, run a paramilitary murdering political opponents on the street.
If one of the most compliant actors is already "virtually unrestricted" then you just want to censor things you don't like and the censorship of porn is just a pretense for the things you actually want to censor.
How can we even trust these lawmakers when Blue Waffles, Tub Girl and Goatsee already existed??!
Unless it hasn't. And while it's grosser than finding a copy of Readers Wives in the park, the "think of the children" angle is overhyped.
These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc. Perfectly privacy preserving. You have no such guarantee when you upload government IDs to a server.
I don't think anyone here minds restricting access, but that doesn't require completely destroying ownership rights over our own devices nor internet and device privacy.
All that really needs to be done is for servers to publish what type of content they show from a parental perspective in a machine-readable format and for devices to have parental controls that only allow access to servers that publish such info and which content is allowed by the parental settings.
This should be even more effective than solutions requiring uploading IDs since there's still going to be servers out there in other jurisdictions that simply don't care for such things.
The problem is that so many people here look at this purely from a USA perspective.
An age check in many European requires no uploading of any ID. It’s an API call toward an ID service, it will tell you which data the service gets access to, and there’s strict regulations and liability around data retention.
I’m not concerned about the government. If they become authoritarian enough to worry, they will impose far tighter surveillance anyway. What we have now is the naive idea that just by not doing ID check, government surveillance is a solved problem in the free democratic world. It’s not. Avoiding ID checks just makes the problem worse because it makes the regular person complacent. The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked. Requiring audits of large corporations. Solutions that give corporations access to only the data they absolutely need and nothing else (the lack of such things is how we end up by uploading whole ID documents)
We can't get perfect privacy so we should normalize not having any? Leave it to the government we're distrusting to handle our privacy?
> If they become authoritarian enough to worry, they will impose far tighter surveillance anyway.
What is this logic? Let's not worry about creeping there because if they want it they'll force it? That's not how it works. Getting to a surveillance state needs acceptance. To get that, rather than dropping people in boiling water, you slowly heat the pot, which is what this is.
Did every American live in a "surveillance state" back then?
Digitalization and now AI technology changes this drastically because it makes it drastically cheaper to record and flag human communications.
Every remote communication could only be had in the clear. Everyone was fine with that. Was the US in the 80s a surveillance state?
Today, and as things continue to progress with speech-recognition, LLMs, video recognition, etc. surveillance can be automated. It's looking conceivable to be able to process all communication population-wide in real-time. That would have been unimaginable back then.
Now, texts and calls today are only a small role of phones. For many people, it's their primary general computing device. It's how they interact with the world. It contains their entire digital life.
Couldn't look at your photo reels and videos, and diary, and every purchase you've ever made, every opinion you've ever said on a public space, every community you've ever interacted with, every location you've ever been in down to the room, from wiretapping a phone in the 80s.
> Some things are exceptionally hard to track now (like e2ee messages) that were trivial to track back then.
Can be easier than back then if stuff like chat-control comes to pass, because now the message can be obtained, processed and stored indefinitely in an automated fashion for everybody at once. E2EE becomes security theater for the most part.
If citizens still have a capacity to restrict the government via (enforced) laws, it doesn't matter much that the communications are in the clear. You can layer something on top just to be sure, but the foundation is laws and a functioning political system.
If there's no functioning political system, the government will just do whatever, like buying the same data they ostensibly can't collect from commercial providers (who weren't restricted from collecting it because there's no US GDPR).
If a country has a functioning political system, it can just do things like ban gun ownership, introduce mandatory IDs, publish everyone's yearly income, or criminalise calling other people slurs in public and not become an uncontrollable dictatorship. If it doesn't, corruption and democratic backsliding will happen regardless. Hyper-focusing on a few tools and superficial traits of a particular system in a particular moment is myopic.
Restricting the government via laws... The government implements the laws. Trying to restrict the government via laws is mostly just asking "pretty-please don't screw us over." They're not going to make a difference to a corrupt government. Government corruption will become more enticing too because of the added concentration of power it would have. How have laws been working for restricting Trump? He's shown how easily they can be sidestepped and manipulated.
Also, back then implementing end-to-end encryption of all calls wasn't feasible. That would have been the preferred option. It's feasible now. We have it. Why rely on something as fallible as government-restricting laws when we have better options?
It's better for power to be decentralized, as it is with every device owner having sole access to their own devices. As well as being able to communicate anonymously, which is huge for matters of free-speech and democracy.
The market failure to provide an adequate solution wasn't natural. It was engineered by the tech companies and you are playing right into their hands. There is still a way to fix this from the root with software antitrust: force hardware vendors to ship their devices without an operating system.
Here's a more detailed explanation in a past comment about how the problem came to be in the first place, and why software antitrust can solve it:
https://news.ycombinator.com/item?id=49118578
Well then, let's regulate this instead? Advertising companies already make a pretty good guess about a person's age. It doesn't require 3rd parties and age verification.
But we won't — this isn't why identity checks are getting lobbied.
> I believe we should shift that liability to advertising.
I am confused. Are you saying that advertising companies should handle these identity checks? So let's just hand out a unique identifier to the companies who have monetary interest in this? Surely this will end well.
Absolute bullshit. This "unfettered access" is the whole reason why I am who I am today, why I am here. Not only did it not fail, it's in fact so successful it threatens the powers that be, and that's the real reason why they want to ban it.
> I personally believe that the easiest thign to attack is advertising to minors.
Now this I agree with. I would be even more radical. It's not just advertising "to minors", all advertising needs to get banned straight up. Advertising is mind rape. Ban it and all the problems with the web will be fixed literally overnight, including the problems "mandated hardware attestation" aims to solve. There is no need whatsoever for this attestation nonsense.
It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
For example, "unfettered Internet access is just a series of tubes (shout out to Ted Stevens for that one) for pedophiles to rape your children." So now what? Is it your hyperbole against mine?
The problem is that people are operating under a myth that they have anonymity. You don't. You're one subpoena away from being unmasked online and individuals can do it (eg [1]). When governments do it, they can do it in secret. National Security Letters, pen registers, FISA warrants, etc.
So the idea that "age verification is the first step to a more comprehensive" is flawed in both logical construction (being a fallacy) and that ship has already sailed.
[1]: https://chambers.com/articles/internet-harassment-lawyer
This is something.
Therefore, we must do this.
How has it failed? Whats the measure of a successful freedom vs an unsuccessful one.
>The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
No its the positive case for action that remains to be justified.
"Arguably" heroin addiction is the most harmful addiction because heroin is the most addictive substance, clouds judgement and drives the addict to all manners of sociopathic behaviour (not only theft or prostitition)
Heroin addiction was largely created by the criminialization of cannabis (the first so-called War on Drugs under Nixon) as a tool to persecute black people and war protesters and the overprescription of opioids (eg the Sacklers/Purdue).
What specific generalized problem would you like to be solved that you advocate for such a generalized solution?
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
For a more detailed explanation of what the root of the problem is, see a past comment: https://news.ycombinator.com/item?id=49118578
Our AI gods cannot save us soon enough.
AI is about many things, but a big factor is enclosure.
You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share.
GrapheneOS is Canadian.
Then if they could give a few millions to some open source communities, that could be the cherry on top
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
Total bullshit.
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
We use that approach in several other industries.
But.... that requires work beyond just complaining.
So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to.
The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care.
For the people who care, it's not a matter of work, because they don't operate the platform.
Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
Come on now.
> minimum security requirements for digital ID use
Also known as "the user has no control over the device".
Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.
> We use that approach in several other industries.
Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
That sounds mostly like copium just to motivate your complete inaction.
Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU.
But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.
Why not tell us more about the requirements for hardware certification?
Seriously doubt it's anything but the usual war on general purpose computing.
Requirement #1, the computer runs the mandated surveillance software.
Requirement #2, the computer does not allow the user to run any software not approved by the government.
Requirement #3, the computer resists tampering so as to preserve the previous requirements.
Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs).
But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment.
So it must be secure against the user, as expected.
Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape.
> But sure, it's a all an evil conspiracy against general purpose computing.
You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this.
Prevents tampering even by the "user".
I have advocated nothing of the sort you're accusing me of. Please leave your strawman at home.
Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away.
It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you.
The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive.
It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online.
So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux.
https://waag.org/en/article/european-digital-id-wallets-are-...
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
Yea, most analysts didn't expect the cookie banner nightmare we're living in either.
To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?
I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.
Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.
The key material must be DRM'ed, especially if some ZKP solution is used.
Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.
(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)
Say you have a public service and a platform site (social media, gambling, whatever), and the user does authentication in a way that anonymously proves to the platform that they're of age while revealing nothing else, and without revealing to the public service what platform they're accessing. But the protocol requires some expensive data (token that provides access to a bond account) which anybody MITMing the protocol can obtain.
Then if Alice tries to sell her age verification abilities to Bob, the protocol could be designed so either Alice learns the negotiated key and can snoop on everything Bob does, or she has to let Bob do a man-in-the-middle over a channel and lose the ability to observe what's going on after the first key exchange; and then Bob can acquire the token and make use of it at a later time.
This is very handwave-ish, but I don't think such a protocol would be impossible to design.
Under normal use, Alice has no reason to drain her own bond account. But if she's selling to an anonymous crowd who might use the token at any time (hence she can't trace the traitor), some troll is eventually going to do it.
I don't.
This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.
It's not like the car refuses to start if a dad tries to teach his kid how to drive.
The alcohol age limit equivalent would be to put the entire TPM + proprietary software infrastructure into the cash register, locking in a monopoly on what software can be used on cash registers. Not to mention, you now have to scan your ID, which then obviously gets recorded forever, allowing the government to track your alcohol consumption.
Yeah, I'm against that and I don't even drink alcohol, not even the alcohol I've bought myself as a gift to my parents.
Firstly, you need to comprehensively ban VPNs, probably with some great firewall setup.
Secondly, you need to install CCTV in people's homes to make sure that nobody uses someone else's device to get around the system.
Then it's time for hardware attestation.
While this is a good point, what's missing here is that this hardware doesn't have to have Google spyware and other bloatware installed. Yet with current design, this becomes mandatory.. security requirements are abused here to force unrelated software on my computer that I have to carry with me in order to participate in society.
This app should work on a dedicated device, something like a smartcard with e-ink display.. it would even be more secure because it would have less attack surface. Just like today I'm not complaining about not being able to install linux on my credit/SIM card, I'd not complain about that either. But locking down the whole OS on my smartphone is unacceptable.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
https://www.youtube.com/watch?v=HUEvRyemKSg
As the internet become the place where people do a lot of things, no government (and especially no security services) will be able to keep themselves from trying to control it or at least monitor it. And with the new LLM features they can automatically do much more than before.
Human nature is a constant and when the government sees an easy way to enforce something, many more bureaucrats will try to do it.
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
- No more shell companies. - Only humans may own shares. - Public ownership registers.
Know thine enemy.
Problem: corporations pushing harmful ads and arranging social media timeline in harmful ways to kids
Solution: restricting the individuals. Giving corporations more control. Giving people less choice.
Yeah makes sense.
That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.
Here's the expected timeline.
The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.
In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.
Don't believe that for a second. Nothing is so permanent as a temporary government program.
Absolute control over people's computers.
It's not your computer anymore, it's the government's.
European "age verification" "app" forcing everyone to use Android or iOS
https://news.ycombinator.com/item?id=48903777
Stop Killing the Internet: No Digital ID and No Age Verification
https://news.ycombinator.com/item?id=49084938
...but then again, this is the EU, not the US.
It does seem like an effort to connect all online activity to real-world identities.
https://diginomica.com/eu-policy-doc-recommends-building-eur...
https://www.europarl.europa.eu/RegData/etudes/STUD/2020/6487...
"Like the Chinese firewall, this European internet would block off services that condone or support unlawful conduct from third party countries."
Sound familiar?
State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
You make it an opt-in feature to "self-broadcast" that this device is being used by a minor. Solves 99% of the use cases. And for the remaining 1% — the really determined teenager — they'd never be stopped by this anyway. They'd social enginneer their way to access somehow.
https://news.ycombinator.com/item?id=46784572
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
If after this is enacted the firewalls aren't perfect, the internet will probably instead splinter into the Westernet and the everywhere-else-net for the rest of the countries that are too disorganized or uncaring to join in on the fun, maybe with a few safe havens of something resembling the old web in between.
The most privacy-obsessed people on earth are now handing a detailed log to their entire digital lives over to a group of barely-elected 3rd party overlords as well as foreign companies and intelligence agencies (if you think this won't be instantly compromised, you're tremendously naive).
...AND at the same time this is cementing monopolies for foreign tech companies within Europe. A double whammy of self-harm.
There's something very bleak about couching this under the 90s-era "protect the children" narrative too, given ultimately most Europeans care so little about children that they've rapidly stopped giving birth to them and in many countries have outsourced all childcare to the state.
It's not even a believable cover story anymore.
It seems more like the European officials looked over at the Chinese Communist Party's authoritarian control over the internet and thought to themselves, "Wow, look how little push back they get to their policies online! I want to do big fancy projects with other peoples money and have no accountability or transparency too!"
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
The head of the EU, Ursula von der Leyen, isn't known to be anti-EU.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
Or do you think, maybe, that there's a deeper issue here and the problem isn't exclusive to just these anti-EU politicians you want to scapegoat?
In order to get legislation you want (say: gay rights) you have to risk legislation you don’t like, for some, that would be gay rights too…
And things that you think are bad, are bad.
Everyone feels this way about their things.
There are plenty of subjective areas where people can disagree without being fundamentally bad people. These things are not those.
What's your position on military spending? Because if we don't spend then our countries get invaded (see: Ukraine) but if we do spend then we're taking money from starving families.. hrm..
I personally have a really hard time, since unfortunately I can empathise with the motivations of others, and everyone has a point, even if I don't agree with it.
The thing is, that I'm aware that everyone thinks they're the good guy, the hero, or the "necessary evil for the greater good", and I find it more interesting to understand why they think what they think is better than what I think.
The alternative means I've already factored the entire populations needs and circumstances, which, for my tiny meat brain which can only empathise with one person at a time is practically impossible.
How did you manage it?
If any entity is "self-sabotaging", it's the European Commission. But it's not self-sabotage, it's simply yet another bureaucratic measure to assert power and control the population.
A surprising little amount of criticism considering the rhetoric in any political right adjacent threads on this website. There are three mentions of 'trump'.