5 ms·
> from a trusted party like a bank. For what reason should I trust a bank?
by win311fwg 20d ago
> from a trusted party like a bank.
For what reason should I trust a bank?
- kees99 20d agoNot "a" bank. You (somewhat) trust your bank, I would imagine. Since you know, they have your money. GP's hypothetical here is that Anthropic or other service provider who wants to do "age verification" could partner with (among others) your bank [1], where bank can answer yes/no to "is this user >= 18?", without revealing any other personal info to the SP. Allegedly. [1] via an intermediary, no doubt. Trying to do a "full-mesh" of partnering of every SP with every bank directly would not scale.
- win311fwg 20d ago> You (somewhat) trust your bank For what reason? > Since you know, they have your money. You may trust them with your money, but does not equate to trusting them with anything else. Principle of least privilege, if you will. Anthropic has your chat data, which in many ways is more valuable than money, so if the only bar for free lying giving out your personal details is trusting a business with something of yours then why bother with this complex scheme and give Anthropic all of your personal information directly?
- petcat 20d ago> You may trust them with your money, but does not equate to trusting them with any other PII. This doesn't really make any sense and it feels like it's just an attempt to be contrarian. Banks by law require substantial PII in order to even do business with you.
- AnthonyMouse 20d ago> Banks by law require substantial PII in order to even do business with you. And those laws are extremely invasive and should be repealed. It's offensive to have a law that de facto requires you to identify yourself in order to pay for a newspaper subscription or buy contraceptives over the internet. But that's not the issue in this case. It's that the bank knows your name and what you buy -- already very bad -- but now you want to create a path to tying that information to everything you do on the internet.
- tayo42 20d agoCan't you pay cash for things like Visa gift cards and use them online?
- AnthonyMouse 20d agoGift cards don't allow reloading which consequently makes them a significant inconvenience to use for subscriptions. It's sort of like saying you can pay for something by going to their offices and paying in cash. Okay, but then why does the way that 99.9% of people are actually going to do it have to be the one that invades their privacy and puts everything they do in a database?
- numpad0 20d agodepends on local laws?
- riknos314 20d agoAt least in the US most places that sell gift cards require ID when purchased in cash
- win311fwg 20d ago> Banks by law require substantial PII in order to even do business with you. That is technically true, but keep in mind that in the early days of banking banks expected you to provide that information without the hand of the law requiring it. The laws you speak of came into effect after the fact to normalize across the industry what the banks were already doing. History is repeating itself in tech, and we already know lawmakers are waiting with bated breath to do their thing all over again just as they did in banking once critical adoption is there. I expect what you are trying to get at is that you are willing to trust a bank because giving them your life story was already normalized before you were born, so you have never thought to question it. Whereas tech doing the same now feels new and scary. However, that's a funny way to look at it as the kids born in the future, who never knew the world where you could use the internet anonymously, will see giving tech their ID as being no different than how you see giving your bank your ID. Although I can understand why you would now question why any business that does little more than store numbers on a computer needs a comprehensive profile on you by law or otherwise. Normalized does not equal sensible. That is a fair point.
- pessimizer 20d ago> it feels like it's just an attempt to be contrarian. You feel like it's an attempt to be contrarian not to inform your bank about everything that you do? Society has reached a dangerous point.
- Capricorn2481 19d agoYou wanna try reading the whole comment?
- win311fwg 17d agoThere is nothing else in the comment except the bit about it being required by law, which doesn't change anything.
- dpkirchner 20d ago> You may trust them with your money, but does not equate to trusting them with any other personal information. How do you expect that they will give you your money when you walk in to a branch and ask for a withdrawal? Or that they'll replace a lost card? Surely you'd expect them to verify your identity.
- AnthonyMouse 20d agoThey could verify your identity if you've given it to them. But it would also be completely reasonable to authenticate the customer exclusively using mechanisms other than government ID. You can already make a withdrawal using your bank card and PIN. If you lose your card you could sign into their website using your password and request a new one etc. Consider what happens if you lose your government ID. Your bank has much better ways to authenticate you at that point than the government does. Government ID has a major bootstrap problem, whereas patronizing a service doesn't because a new account with no money in it belongs to whoever is signing up for it regardless of who they are, and you can at that point give them a bank card and have them provide a password and email address etc. that allows you to identify them in subsequent transactions without ever needing their name.
- win311fwg 20d agoWell, how do you expect a website to know that you are 18+? The technical solution offered earlier was to have a trusted third-party only be willing to answer the "is this person 18+?" question. Of course, the same works for banks. The trusted third-party can answer "does this person own this account?" without needing to reveal to the bank any other information about you. Now, that still leaves open the question of who you can trust. If you can trust a business run by people then that allows you to trust a bank, sure, but it also allows you to trust a tech company, so why not just give the tech company your ID and skip all that technical complexity? Understandably the broader idea presented earlier was that you cannot trust businesses operated by people, but then that includes banks, so... For the sake of discussion, if we accept that technical solution and the need for a trusted third-party that is a business run by people, surely it should at least be a business that does nothing but offer profile trust to minimize the blast radius? For what reason would we want that business to have their hand in other activities like chat or banking?
- deaton 20d agoI trust my bank a whole lot more than I trust Anthropic
- win311fwg 20d agoIf I had a bank, I'd trust it too, it being mine. Most people don't have the luxury, though. In practice, they have to outsource banking to other people. And those other people are already quite likely to move around between both Anthropic and various banks in search of whomever will offer them the most economic benefits. It is not like a particular logo on their current business card is going to change their character. You do you, of course, you are already unique in having a bank you can call your own. But the fact remains that most people strongly believe that a person's trustworthiness is of the person, not the activity they happen to be doing at the time.
- deaton 17d agoCome on, you know what I meant. You don't need to aggressively and intentionally misinterpret my point to make yours. I trust the company with whom I store my money to generate attestations of my age without leaking additional information more than I trust the company who has stolen every piece of human text ever written to train their chatbot.
- win311fwg 16d ago> stolen every piece of human text ever written Those who argue copyright infringement have a somewhat compelling claim, but stolen is a little out there. Especially since text I have written has provably never been stolen, making "every piece" impossible. The underlying trouble with the copyright infringement claim is that it forgets that copyright was extended by the people as a construct to help foster innovation so it expected that the same people would ignore/revoke copyright claims where the product of its use is seen as a greater innovation. Copyright is but a human-created tool, not some natural law of the universe. I understand also that not everyone sees AI as a worthy innovation, but societies do not function on the whims of a few people.