3 ms·
How do I prevent my citizens from sharing their certificates in order to bypass the block?
by sleepychu 1y ago
How do I prevent my citizens from sharing their certificates in order to bypass the block?
- CaptainOfCoit 1y agoYou don't, it's up to citizens to make sure whatever authentication they use can only be used by them, just like how it works for other services today where you authenticate online somehow and the government service assumes you're you since you were able to authenticate.
- sleepychu 1y agoMy point is that this is either a bearer token (in which case it will be obtainable by proxy) or tied to your identity. What is the incentive for the citizen to make sure their authentication isn't shared?
- owisd 1y ago> obtainable by proxy So no different to the rules around buying an 18+ DVD.
- CaptainOfCoit 1y agoOn the government endpoint, which returns X that the platform uses as "evidence" for you being an adult, yes, that's tied to your identity, as the certificate/whatever is tied to your identity. But as long as the platform who need to validate that you're an adult don't get your identity, but just the proof, I don't see what the problem is? > What is the incentive for the citizen to make sure their authentication isn't shared? What incentives do people today have for keeping their identifications to themselves? Why aren't we all sharing CC numbers? Because we realize some data is "personal" and isn't to be used by others, like our username+passwords or whatever. This isn't exactly a new concept, just look at how it works for anything else that is tied to you.
- mrmanner 1y ago> On the government endpoint, which returns X that the platform uses as "evidence" for you being an adult, yes, that's tied to your identity, as the certificate/whatever is tied to your identity. In this scenario the government knows all the age-restricted sites I've visited. I'd argue that is worse than if all the age-restricted sites I've visited know who I am... (FTR I don't know what I think about age restrictions in general, but I'm pretty sure there's no implementation that comes without negative side effects)
- Ajedi32 1y agoNot necessarily. The age verification proof doesn't need to be site-specific. But again, that reduces the incentive "for the citizen to make sure their authentication isn't shared" because there's nothing tying it to them. I also kinda hate the whole idea of needing explicit permission from the government to access the open web, regardless of whether or not they know which specific sites they're giving me permission to access.
- immibis 1y agoThere's actually a much better idea that's been floating around. Require over-18 sites to set a certain header. Then anyone who wants to can install a browser on their kid's device that will block pages with the header. There's no privacy implications, no surveillance implications, no need to make VPNs illegal as long as they pass it through; it's just a plain old parental block with a regulation keeping it always up to date. Yes, you may have to stop your kid installing random software on the device to bypass whatever blocking you set up, but you had to do that anyway. If it's Apple or Google they could easily enough require everything in the app store to respect the flag when the device is set to kid mode. (If the government does the incredibly overbearing thing and does not do the simple and effective and unintrusive thing, it proves their motivations are surveillance)
- gjsman-1000 1y agoAlready exists; the industry called it RTA (Restricted To Adults). Nobody used it... and it's 19 years old. Complete failure categorized under "we already tried that." https://www.rtalabel.org https://www.rtalabel.org You can use it too, just put this in as a meta tag: <meta name="RATING" content="RTA-5042-1996-1400-1577-RTA" /> Or send the following header: Rating: RTA-5042-1996-1400-1577-RTA
- ashdksnndck 1y agoHow do they solve this for e-voting?
- magicalhippo 1y agoFrom what I can gather from the EU proposal[1], they rely on such details to be stored in a hardware crypto module on a phone or similar. Thus the user never has direct access, yet can use it to issue proof of age. [1]: https://ageverification.dev/av-doc-technical-specification/docs/architecture-and-technical-specifications/ https://ageverification.dev/av-doc-technical-specification/d...
- wkat4242 1y agoThis is even more Draconian because it demands that citizens rely on manufacturers. After all the government itself doesn't make phones or hardware crypto modules.