5 ms·
Whenever this comes up, the focus is on simply opposing the idea. I think perhaps devoting energy to solutions that can address both the concern of safety and p
by Edmond 2y ago
Whenever this comes up, the focus is on simply opposing the idea. I think perhaps devoting energy to solutions that can address both the concern of safety and privacy is also worth considering.
The internet is going to be a fundamental part of human life I would argue indefinitely. The need for robust information verification is not something we're going to be able to do without.
The question is, would solutions end up being effective ones or ones that "work" but create all sorts of other problems? The worse outcome in my view would be that we all end up being required to use big tech companies as gate keepers for our digital lives.
Now for my pitch :). Cryptographic certificates are a solution option that CAN bridge this gap.
App:
https://certisfy.com/ https://certisfy.com/
Demo:
https://youtu.be/92gu4mxHmTY https://youtu.be/92gu4mxHmTY
Technical Doc:
https://cipheredtrust.com/doc/#pki-overview https://cipheredtrust.com/doc/#pki-overview
- fidotron 2y agoRespectfully, you are making the error of assuming it is a technical problem when it is a political one. The problem the government have is the masses trust those bad people over there more than our trusted and approved government experts over here, and they think this is a communication problem and not a problem of substance. I would agree that technical measures for trust are necessary, but the gov should not be allowed to be the arbiter of who gets to trust who - that is a fundamental freedom that must be left to individuals.
- ranger_danger 2y agoOne could also argue that the problem is actually educational.
- nvy 2y ago>Whenever this comes up, the focus is on simply opposing the idea. Well, because the idea is fundamentally unsound. Nobody can keep such a database secure, and certainly not the Canadian government, champions of ineptitude that they are. >Certify Goodness, that's dystopian.
- Edmond 2y agoIt doesn't require maintaining a database. The certificates can be in a registry but also can be on your device without being in a registry. In any case, the security is not associated with a database or anything of the sort.
- nvy 2y agoOkay so what happens when I lose my keys and need new ones issued? I have to go through the manual verification process and then issue revocation certs for my old keys? How do I know what those keys were without a database of which key belongs to whom?
- Edmond 2y agoYes if you lose your keys you do have to get new certificates and if possible revoke the lost keys. Revoking certificates will require either a revocation code that is issued when you get the certificate or you can use a copy of your private key to issue a revocation request. If you don't have a revocation code or a private key for the cert you wish to revoke, it will require administrative access to the certificate registry to mark the cert as revoked. That feature is currently built into the platform but not something accessible because of the obvious challenges. Your private keys are only known to you, certificate revocation is just an annotation that says to someone who receives a signature associated with that certificate to not trust the certificate. All private keys are generated and stored only on your device.
- nvy 2y agoOkay so we've established there must be a central registry, since it's a certainty that somebody's 65 year old mom will lose her phone and her certs and keys with it. How does your system protect against attackers claiming to be my mom?
- axelthegerman 2y agoA QR code verifying that I'm 18 years old, great! What use is that? Not sure... anyone could copy that QR code and claim they're 18 years old. Or maybe it includes more data than that and we're back at the privacy problem.
- Edmond 2y ago>A QR code verifying that I'm 18 years old, great! What use is that? Not sure... anyone could copy that QR code and claim they're 18 years old. Exactly, now scan the sticker with the QR Code on this blog post: https://blog.certisfy.com/2024/02/from-secrecy-model-of-information.html https://blog.certisfy.com/2024/02/from-secrecy-model-of-info... You'll see it tells you whether the sticker is stolen or not based on where you got it from, ie the "Valid For Source" field.
- axelthegerman 2y agoExcept that being on a phone I can't scan a QR code being displayed on the same device. But basically you're saying that I need a QR code for each site I'm using? That's not obvious from reading the blog post. And still doesn't address that someone else could use the same code on the same site? Also I don't think I understand what "the secrecy of your social insurance number/credit card doesn't matter as long as nobody else can generate a certificate for it" means. Is that assuming everyone only accepts certificates and not the raw information anymore? I'm sure fraudsters would happily take credit card numbers even without being able to generate certificates.
- Edmond 2y agoThe QR code is just a convenience feature. If you look at the sticker you see a short alpha numeric code, that's what's on the QR Code. You can type that alpha numeric code into the Certisfy app to verify the sticker: https://certisfy.com/app/ https://certisfy.com/app/ You'll probably never use a social security certificate directly, it will be used as a IRL "identity anchor" certificate as described here: https://cipheredtrust.com/doc/#pki-id-anchoring https://cipheredtrust.com/doc/#pki-id-anchoring Yes a fraudster will happily take a stolen card but it will be of no use to them if they try to use it via Stripe for instance to post a charge but Stripe requires a cryptographic signature for a certificate for the card :) So sure the card processor has to require the signatures to make it effective. In other words the secrecy of the card number becomes irrelevant if it requires a certificate signature before it can be used, only the owner of the card has the private key on their device to generate the signature. Secrecy is still useful for privacy.
- soared 2y agohttps://developers.google.com/privacy-sandbox/protections/private-state-tokens https://developers.google.com/privacy-sandbox/protections/pr...
- braiamp 2y ago> Whenever this comes up, the focus is on simply opposing the idea What are you saying? We have been proposing solutions since immemorial times. If it's bad for the kids to have access, why it is not bad for the adults? If you can answer that question the solution should be evident.
- ranger_danger 2y agoIt can be argued that it's bad for both. I think the solution is an educational one.
- pdonis 2y ago> The worse outcome in my view would be that we all end up being required to use big tech companies as gate keepers for our digital lives. So your proposed solution is...to give my private data to big tech companies? Who else is going to manage the cryptographic certificates at scale?
- Edmond 2y agoThe keys are on your device, it doesn't require management by a third-party.
- cwillu 2y agoThere is zero chance that a legally mandated certificate scheme won't require centrally-managed certificates to prevent the underage from loading illegally shared keys onto their devices.
- Edmond 2y agoCertificates are not things that are centrally managed. If you get a certificate from a CA (DigiCert, AWS,Google...etc), they hand you the certificate after necessary verification but otherwise have nothing to do with how you use (TLS traffic) it. The same with something like age verification. Once you have a certificate that attests to your age (as of certificate issue date), the issuer has nothing to do with how you use it, the receiver of signatures generated from that certificate (via private key) can verify it without any interaction with issuer. As for misuse, that's certainly a concern but it can be addressed via the issuing process. Certisfy does address this issue. A fundamental requirement for making a certificate scheme work is that certificates are anchored to IRL identity via identity anchor certificates in a privacy preserving manner. You can read up on the approach here: https://cipheredtrust.com/doc/#pki-id-anchoring https://cipheredtrust.com/doc/#pki-id-anchoring
- ranger_danger 2y agoDid you just forget that CAs exist? They are centralized. You always have to trust SOMEONE. Even if it's the person that wrote the CA software being used, or the supply chain that provided the software to a vendor, or or or. See what I mean?
- qwerty456127 2y ago> Whenever this comes up, the focus is on simply opposing the idea. I think perhaps devoting energy to solutions that can address both the concern of safety and privacy is also worth considering. This implies you have to be concerned about safety. But I don't believe seeing anything [they would voluntarily watch] on a computer screen can inflict serious harm to anybody, no matter the age. I advocate for universal (without exclusion of any age group) right for anonymous access to whatever information already is publicly available.
- kelipso 2y ago> But I don't believe seeing anything [they would voluntarily watch] on a computer screen can inflict serious harm to anybody, no matter the age. You can believe whatever you want but a whole lot of people including me do believe watching shit, voluntarily or otherwise, harms you. Plenty of evidence for it.
- qwerty456127 2y agoI actually do believe everything does harm you in at least some minuscule degree (even things that help you in a way or many, harm you in another). Even breathing does. Yet the degree of harm is not substantial enough to justify prohibition and all the downsides coming from trying to enforce it. Being a generally normal person I also feel I wish kids see no porn yet as soon as I direct my attention to this feeling and question it I recognize it has no rational reason whatsoever, it's just as subjective as a preference can be. Banning a specific kind of content would be as reasonable as banning a food I personally don't find tasty, even if the majority feels the same - should we waste everyone's effort and sacrifice everyone's rights in such a case?
- kelipso 2y ago> no rational reason whatsoever There are lots of rational reasons including distortion of sexuality, lack of interest in real world sexuality, depression, etc.
- sys_64738 2y agoThe reason it comes up is because it's the proverbial wolf in sheep's clothing. Conservatives have an agenda to remote porn from the internet at all costs. They also want to kill anonymity on the internet and if you frame it properly then you can push through their agenda.