3 ms·
I appreciate the sentiment I guess, but you can't really verify the human-ness of a poster. At best you can validate that at some point(s) they completed a huma
by recursivecaveat 5mo ago
I appreciate the sentiment I guess, but you can't really verify the human-ness of a poster. At best you can validate that at some point(s) they completed a human-is-present check. Doesn't necessarily mean anything about a given post. Moltbook (wow that feels like forever ago) has the inverse problem: you can just larp as a kooky bot. At best maybe you can do something like limit the number of bots to the number of people who are willing to set aside their personal credentials, which is probably way more bots than you can stand.
- perching_aix 5mo agoThey could tie the identities to governmental identities in a blind manner. The pitfalls are as follows: - the governments can just arbitrarily manufacture identities - identities (govt and this) can be stolen - identities can be misused (coercively or consensually, e.g. by passing on access to another person or automation) Still would beat the current state of affairs, which is piss-all identity attestation, but then they're not actually doing this. They're scanning official documents and go LGTM + pinky promise. Hard skip.
- pixel_popping 5mo agoWhen sending identity to a remote server in cleartext, you must assume that you are giving away the data associated with it, it's just basic security principles, if the engineers behind this don't care enough to KYC using cryptographic ways which already exists, then you can be sure there is some sort of incompetency and/or malice :) If I browse an http website, then I know that someone could be using the data, if I put my passport somewhere, then I know someone could as well, apparently having thousand of leaks every year isn't enough of a proof to people :/