3 ms·
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as lo
by tzs 2mo ago
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
- _jackdk_ 2mo agoAnd how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
- petcat 2mo ago"Most analysts" actually expect the opposite: https://waag.org/en/article/european-digital-id-wallets-are-gift-google-and-apple/ https://waag.org/en/article/european-digital-id-wallets-are-... Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
- matheusmoreira 2mo ago> Most analysts expect Total bullshit. There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking. The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense. Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society. This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
- izacus 2mo agoYou can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use. We use that approach in several other industries. But.... that requires work beyond just complaining.
- matheusmoreira 2mo ago> You can of course create an independent attestation database at any time Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. Come on now. > minimum security requirements for digital ID use Also known as "the user has no control over the device". Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it. > We use that approach in several other industries. Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
- izacus 2mo ago> Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. That sounds mostly like copium just to motivate your complete inaction. Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU. But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.
- matheusmoreira 2mo ago> we're using similar approval processes across multiple industries to certify hardware Why not tell us more about the requirements for hardware certification? Seriously doubt it's anything but the usual war on general purpose computing. Requirement #1, the computer runs the mandated surveillance software. Requirement #2, the computer does not allow the user to run any software not approved by the government. Requirement #3, the computer resists tampering so as to preserve the previous requirements.
- pembrook 2mo agoI literally lol'd at the "Most analysts expect..." line. Yea, most analysts didn't expect the cookie banner nightmare we're living in either. To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse.