13 ms·
Yoti age checks share facial photos and device fingerprints with third parties
- gum_wobble 4mo agoYeah, well, I mean, ahah, you don't say :)
- falsaberN1 4mo agoThere isn't enough noise about this kinda news. People need to learn to distrust such systems and exposing failings such as this one is a good way to do it. We aren't going to be free of this stuff until the average Joe's mom hear of "forced age verification" and associate it to "unsafe".
- pmh 4mo agoThe paper is https://mikespecter.com/assets/pdf/AgeVerification.pdf https://mikespecter.com/assets/pdf/AgeVerification.pdf (good on them for linking it) The rest of the IEEE Symposium on Security and Privacy papers are listed at https://sp2026.ieee-security.org/accepted-papers.html https://sp2026.ieee-security.org/accepted-papers.html
- Tanoc 4mo agoI've been telling people for years now not to engage with systems such as these. Some say I'm just being paranoid. But a growing number concerningly reply with either "So? What are they gonna do with it?" or "They already have it, it doesn't matter." Normal people either don't know the dangers present or they don't understand that stopping the flow hurts the machine. And they want neither to know or understand. Apathy or the desire for convenience cannot adequately explain why.
- AlienRobot 4mo agoWhat I'm afraid of is that this is all a ticking bomb that is going to explode VERY hard on the most technologically vulnerable.
- PaulKeeble 4mo agoAll this biometric data is setting people up for identity theft attacks. These types of attacks are going to grow enormously over the coming years as biometric data is gathered and leaked on a massive scale. Anything put on the internet has been leaked already, almost every company with a web presence has lost data. Biometrics unlike passwords, phone numbers and credit cards can not be changed.
- quantummagic 4mo agoAnd that assumes a relatively stable environment; but politics can change drastically for the worse. We have examples from relatively recent history of governments turning evil, rounding up unfavored groups, and shipping them off in rail cars to an early demise. God forbid it happens again with all the information available to sort, categorize, and identify people.
- joshuaissac 4mo agoWhat can people do? Systems like these are mandated by companies that provide services that people need, and they are hard to avoid. In-person verification is sometimes an option but not always.
- Grom_PE 4mo agoSince those people don't care about privacy and anonymity, perhaps they are also willing to trade by verifying for someone who does care?
- diegof79 4mo agoBut what is the alternative? Many of these systems are added to digital wallets due to legal requirements or fraudulent cases. For example, one case of fraud that I’m aware of happened in Chile, where citizens were able to open bank accounts digitally with just their ID. But since there is no good biometric information, many criminals took the IDs of homeless people to open accounts and move money around. Sadly, these shitting things happen, then companies use these services to avoid the liability, and then these services abuse the information they have. People don’t have much choice unless their representatives in government do something; it’s not about apathy: you can stop using one bank app, but not all of them otherwise you’ll be out of the financial system.
- rockskon 4mo agoI recall at an old place of work, the security office having a poster on the wall that said something to the effect of "if your facial biometrics get compromised, you must change your face". Silly as they were trying to be, the concept still holds - Facial biometrics can and do get compromised too. Your example of IDs taken from the homeless - what the heck prevents organized criminals from taking pictures or recordings of their faces too? Already there's malware out there stealing facial recognition data from infected devices (ESET reported on this nearly two years ago). Unlike changeable passwords, once your facial recognition data is compromised then that's it. Scammers can now impersonate you on top of having defeated this additional layer of fraud prevention.
- GuB-42 4mo ago> Normal people either don't know the dangers present But what are the dangers? I mean concretely, in a way that can affect their day to day life, with significant probabilities. HN is a tech forum, people here are very aware the tech risks. But talk to anyone in a given field and they will find a way to scare you. Don't go out in the sun without SPF50 gear or you will get cancer, your house electrical system is a fire hazard because you don't have the latest breakers, buy a gun, don't buy a gun, have this and that survival equipment, learn self defense, never talk to the cops, don't leave your drink unattended,... At some point, people just want to stop worrying and do their things. And guess what, most people are fine! In fact considering how many things can turn bad, normal people are rather good at avoiding the worst despite an apparently carefree attitude. Meaning they are not so bad at evaluating risks, and that society has pretty good guardrails. So cut normal people some slack unless they are in immediate danger (for example if they are in the process of responding to fishing), uploading their picture to Yoti is not that. They have other worries in their own field. Inform them, but don't press it, and if you are in the field, your job is to help normal people be carefree, not cause more anxiety, they have more than enough already.
- Tanoc 4mo agoOne of the dangers is in the ability to cross-nationally attack someone. As digital infrastructure continues to encompass more and more facets of necessary interactions with the government and governments force more and more points of interaction someone from a foreign nation could destroy the life of someone who is interfering with their aims. Say someone has published an article that reveals the terrible behaviour of a given company. Someone hired by the company can use a variety of data points to not only track down who that person is, but where they live and even which room in their house they spend the most time in. With that kind of information it would be easy to financially, reputationally, or mortally wound someone. With the worryingly swift growth rate of corruption this could apply at any level for any reason. And unlike for example the difficulty of getting into a car crash or robbing a cash register, digital infrastructure makes all of this remarkably easy and for some parts even free. With modern LLM agents it could be entirely automated so that no human is ever involved, and because there's so few current guardrails and such a vehement protestation against any being implemented the agent could wipe it's connection to it's handler so that nobody ever faces any consequences. The thing is, this kind of stuff already happens all the time. The number of spam calls people suffer through are a direct result of companies digging through the contacts list after being granted that permission (though often without being granted that permission), then selling that data to brokers. Data breaches that wipe people's credit or force a credit freeze because they bought something ten years ago are another common one. Or think about package stalking, where people get access to someone's purchase history and the tracking number to a purchase so that they can steal it in transit or once it arrives. There's a number of beatings and murders that have happened because of police officers being able to access surveillance tools to track former romantic partners or spouses. All of these are different parts of the lack of privacy, and they're all getting worse because the tools that are used to surveil are becoming more widespread and more accessible. Privacy is a protection against the intelligent attacks of other humans. It is not a frill that can be taken away without ridiculous and trailing harm.
- Havoc 4mo ago>not to engage with systems such as these Yoti is used by governments. Principled stances are all good and well for hn comments but eventually collide with reality
- Tanoc 4mo agoGovernments, regardless of what threat they wield against those they supposedly govern, are limited by the fact that they are organizations run by humans. For now. God forbid we ever reach the point where there are no humans... Anyways, because of that they require humans to ensure enforcement. A major reason why Yoti is able to do what it's doing is because there are no humans enforcing privacy and data protection laws against them. This means the reverse can also be true, where enough people motivated to do so can simply not enforce whatever requirement there is for Yoti's services to be used. Because the social contract's been not only breached but shredded and spread to the wind this is very likely to occur. In my viewpoint unfortunately the most likely reason is because they'll go with somebody else other than Yoti that provides more favourable terms, but that's an aside to the likely situation I outlined.
- ian_holt 4mo agoIn addition, to the fact that governments are still run by us mere mortals, is the fact that even the government is unable to 100% to guarantee that our data is "safe" in their hands...
- Havoc 4mo agoAn admirable principled stance that just doesn’t fucking work in the real world. Government processes and staff have zero interest in such stances. Next time you go through a border control try refusing to be searched or scanned on grounds of privacy and see how that goes for you. Lay the chat about broken social contract and how governments are a threat thick enough and officials may decide it’s better if you’re not on a plane at all
- Tanoc 4mo agoDude I'm likely on so many lists already it doesn't even matter. Considering the government of my nation is currently levying new threats against the citizenry just about every day it's not even that much to talk about. I'm just hoping that enough people can be convinced that systems of governance are not immune ethereal constructs run like videogame logic where you cannot do anything not explicitly written down. Too many people think that enforcement of anything works like a zap from God instead of being a mechanism that needs enforcers to pull it off.
- wmf 4mo agoEvery app shares all data with third parties. The concept of privacy labeling has completely failed and it's time to try a new approach.
- gruez 4mo ago>TABLE 2. USER AGENT METADATA FIELDS (“CLIENT HINTS”) SENT AS PART OF YOTI’S AGE ESTIMATION METHOD As far as device fingerprinting goes, this is pretty tame, compared to what something like chatgpt does: https://www.buchodi.com/chatgpt-wont-let-you-type-until-cloudflare-reads-your-react-state-i-decrypted-the-program-that-does-it/ https://www.buchodi.com/chatgpt-wont-let-you-type-until-clou... The far more concerning part are your pictures/document scans getting sent to them.
- beloch 4mo agoIf a city hires a cop who openly accepts bribes, it's a problem for city hall. If they tolerate crooked cops, they are rightly painted as being corrupt as well. If a government mandates age verification and tolerates companies like Yoti as enforcers of their law, it's exactly the same thing. If politicians aren't willing to see that new laws are enforced with integrity, then these corrupt politicians are the problem and need to face the consequences.
- AntosTools 4mo agoYou're right but its not just the politicians unfortunately, one of the main reasons the general population isn't acutely aware of these kinds of occurrences(Yoti is not the only culprit) is because major news outlets don't give these stories the time of day. If were putting blame on politicians for their contributions to this problem we should also do the same for political news outlets. If they had a shred of moral decency and weren't corrupt they would allow and want this news to spread openly.
- Waterluvian 4mo agoWhy stop the logical chain there? The people are to blame for making garbage media more profitable than real news.
- truthfinder61 4mo agoCan you explain what is the bribe here? Company A hires company B to offload the burden to do age checks, company B takes the burden to do it securely and only returns an age result to company A (no personal identifiable information). Company A here could be any site, they are good at creating content, they should not be processing sensitive data. Company B is the expert, their job is to process personal data, confirm age, destroy data.
- beloch 4mo ago"The research team determined that the process Yoti uses to verify a person's age broadcasts the person's personal information to third- and fourth-party companies." "When a bartender checks an ID, they quickly verify a customer's date of birth and identity before serving them. Companies like Yoti that employ digital age verification claim their products function the same way, but in a completely private manner." ------------- Company A is not the problem. They called the cops to do cop things. That's fine. Company B (e.g. Yoti) is the one that's operating like a cop. If Yoti is getting paid by those it shares user data with, that's corruption. If they're not being paid, then it's mere criminal negligence. If governments are to mandate age verification, then they also need to implement privacy standards for the gatekeepers and enforce them.
- SwellJoe 4mo agoAge check is identity theft at scale, mandated by the state. A disaster waiting to happen (and it won't wait long).
- internet101010 4mo agoThe third-party list on page 12 is not small. The real-time api architecture creates a live, per-query link between a specific user event and every broker in the chain. Batch transfers or delta shares would break that linkage. Zero-knowledge proofs (also mentioned in the study) can prove age without handing anyone a name, document, or photo. There's no reason Aristotle or Veratad should see who the underlying requestor is. Yoti should receive the verification request, strip the context, make the request - that's it. The fact that it isn't structured that way and they are tagging on additional metadata suggests per-query economics, which creates a direct incentive to route more verifications through more parties, exactly backwards from data minimization. I'm not going to call it a rev share, but the architecture is consistent with one.
- rockskon 4mo agoWhile I agree with your claim that it is likely the number of third parties info is being routed to is likely related to per-query economics, I want to note that ZKP are not magic. They tend to either be worthless at preventing fraud or require so much additional context as to question how much privacy is really being preserved. While ZKP is more useful in limiting how much info is provided and, depending on implementation letting you make sure of the full scope of information acquired....if it literally only validates age then there's nothing other than logistics preventing a single adult from authenticating the entire world.
- internet101010 4mo agoTotally agree. Was just trying to emphasize that there are better ways to do this if privacy and security are something that Yoti actually cares about. ZKP is not a magic bullet.
- unknown_user_84 4mo agoProbably worth mentioning that I just did a very informal and quick review of identity/age verification providers because of payment provider requirements. Yoti came up as one of the more privacy focused (relatively) lower friction options because they only require a face scan and try to estimate age based on that. They may do more but that is as far as my research got.
- shreyasminocha 4mo agoLead author here, happy to answer any questions about the study!
- truthfinder61 4mo agogreat, how does it feel to be used for some political end goal, shouldn't technical people stick to facts, instead of speculating
- truthfinder61 4mo agoWe are definitely entering the era of stupidity. Who wrote that article hasn't read the paper, just asked some AI to scan it and fudge up an eye catching article. The article claim things that are not in the paper, that are actually false, the paper does state the face image is actually encrypted on the client side and never says that is shared with third parties. If you prompt your AI with enough bias and ask it to read a technical paper, then this is what happens. And given no one bothers to check facts there you go, everyone screaming against a legit company that is just doing its job. The paper itself reports that Yoti has given an amicus brief in a US court where they just stated that age verification can be done in a privacy preserving way (which seems to be what they do, they have nothing to gain from keeping data). I wonder if that is why they are after Yoti so badly now.
- ChrisArchitect 4mo agoUpdate since submission: An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements https://www.yoti.com/blog/open-letter-to-georgia-institute-of-technology-university-of-california-irvine-requesting-retraction-correction-false-statements/ https://www.yoti.com/blog/open-letter-to-georgia-institute-o...
- Mindwipe 4mo agoThe fact this letter takes aim at something the paper doesn't say is pretty damning. The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties, including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with. Yoti's letter then gets angry that "face" data is not passed to third parties. That is not what is alleged. Not to mention the repeated veiled threats about how they "could" sue academics investigating their systems. It is absolutely incredibly sus as a letter.
- truthfinder61 4mo agoHey Mindwipe, 100% agree the paper doesn't say that face data is passed to third parties, but then the techexplore article from those universities DOES. That article is the one that this whole thread started on, strangely you are ignoring that. What's pretty damning is that you make it appear like you know the paper but you claim things that the paper doesn't claim. In the exact same style of those who wrote the article, interesting. You claim that "The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties" That is FALSE, the paper doesn't say that, it actually says that the high entropy metadata is sent to Yoti servers, actually encrypted with client side keys on top of TLS which makes it impossible for any third party to even read it. Reporting here extract from the paper: --- Once the user’s face is properly aligned, the SCM collects and processes a significant amount of data that is sent to Yoti’s servers. In particular, it collects the photo captured from the user’s camera and telemetry, including significant high-entropy browser and device metadata (see Table 2). It also includes data about the camera’s properties, the FPS of the camera stream, and metrics about download and processing times. The SCM uses some cryptography, which we briefly describe here before returning to its implications in Section 5.5.3. If the image encryption setting is enabled (as it is by default), the SCM encrypts the captured image using AES-GCM with a key and initialization vector (IV) derived in the browser. Similarly, the telemetry and metadata collected is also encrypted under AES-GCM in the browser. --- Then you claim "including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with." Which perfectly highlights the issue, as it seems like you might have gotten that from the Abstract section of the paper. The great thing is that the paper itself disproves all of that when you read all the details. And anyone can find out that the key section where there is actual sharing of data with third parties (not the visiting site) is when the credit card check method is used for example. Which is pretty inevitable, to do a credit card check you need to use a payment provider which will have to process the data necessary to do that.