Please look a the video it will explain the problem whole lot better than I ever could. But if you think it is important please sign the petition.

The EU Commision is rolling out a law that will severly impede our rights when it comes to digital products.

  • Carl@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    6
    ·
    edit-2
    23 hours ago

    I’d be fully in favor of hardware-level age verification. And by that, I mean we already have the technology to securely and privately verify your age directly with the government, (not using a third-party), and so no single organization has a chance to collect more than a salted hash of your info. Then your user account (or the entire device, if you’re using a phone) would be considered verified. It would require governments to actually cooperate and be technologically literate, (which… Yeah… I know that makes it a pipe dream) but it is technologically feasible to implement.

    The short version is as follows:

    1. Governments have citizens create a password. Ideally this would happen when they’re applying for their ID, which they would need to have to verify their age anyways. This password and salt is used for their hashed info.
    2. The government sets up a database of salted hashed info, along with a simple Boolean pass/fail for whether or not the individual is an adult. Again, this is only using salted hashes, (the same method we use to securely store passwords) so there is no recognizable data even if it gets intercepted in transit.
    3. The government publishes a service that intakes a hash, and returns a true/false for whether that hash matches an adult in their database. Again, no actual PII is stored in this database, only salted hashes.
    4. The user who wants to verify their age inputs their info into their device using standardized inputs, along with the password they created when they applied for their ID. This is hashed directly on the device, just like a password is hashed before it is sent to a website. This hash is the only info that leaves the device.
    5. Whatever service that is trying to verify your age takes this hash, passes it to that government database, and receives a pass/fail result. If you pass, your age is now verified. Congrats!
      (a) Note that the company never received your PII, they only received the salted hash, and only received a basic Boolean 1/0 response from the government server. They never even received your exact age.
      (b) Note that the government never received any info about your device, so they can’t use it to track you at a hardware level. They simply saw Microsoft/Google/Apple/etc. asking about a hash.
    6. Now that account is verified, and can be used to automatically bypass any age-gates on any devices it is used on.
      (a) For example, if your Microsoft account is verified, any computer you log into with it will also be verified while you’re logged in. If your Apple/Google account is verified, your phone/tablet is verified when you’re logged into it. This could also allow adult accounts to set up restricted child/teen accounts for shared devices like desktops or tablets. Allowing those children/teens access to age-appropriate content without needing to deal with verifying them independently, because the child/teen account was made with a verified adult account so the age range on those restricted accounts can also be trusted.
    7. This could even cut out the middleman and verify the device directly using that same government service, but that would need to come with some extra security precautions (which I’m not smart enough to devise) to be sure the government isn’t able to collect verification attempts and tie individuals to the specific hardware devices that made those requests.

    And then the verified device can directly pass a “yes this user is over 18” flag directly to any service that needs it. Sites simply ask for an age range. A verified account would automatically respond as “Adult”. A restricted child/teen account (created by a verified account) would automatically respond with “child” or “teen” respectively. And an unverified unrestricted account wouldn’t respond (or would respond as unverified) which would prompt sites to automatically hit them with the age verification gate. This age range check could all be done securely during the initial TLS handshake, before the site even begins to load. Ideally, it would be a fairly wide age range, to prevent data collection services from simply going “oh this user was reporting their age as 14 yesterday and now they’re 15. Now we know their birthday is today.”

    This would all allow websites and services to verify ages on the backend, without actually needing to use third-party services. It would also allow for a much smoother user experience, with verified adult users being able to automatically bypass any kind of age gates. And unverified users trying to watch porn would probably automatically get redirected to a “your device isn’t verified, here is why, here is how to verify it” page. No concerns about kids lying and clicking the “yes I’m over 18” button, because they never even see a button to click. They just immediately get redirected to YouTube as soon as the site sees that they’re not verified as an adult.

    It’s really the best of all worlds. It allows for secure verification, where the only info leaving your device is scrambled. It appeases the “think of the children” politicians and allows them to put their name on something. It allows us to ditch the stupid fucking “click here if you’re over 18” pages. And most importantly, it would actually protect kids, because now preventing them from accessing mature content is as simple as protecting your passwords. Because your kid can’t just steal your ID to verify their device without also having your password.

    But again, none of this will ever happen because the data companies are the ones pushing for age verification laws. They want to insert themselves as the only viable third-party for verification, because they want to be able to collect all of our data. And that means the inevitable age verification methods will be the least insecure, most invasive methods imaginable. I’ve been saying for a while now that we should work to give politicians a better method, to stop them from implementing the worst shit that lobbyists can pay for. But lobbyists can pay, so their suggestions will go a lot farther even if they’re less secure.

    • Ftumch@lemmy.today
      link
      fedilink
      English
      arrow-up
      5
      ·
      23 hours ago

      Ok, so let’s say you’re a minor and I get a hold of your hash. Now I’m going to run it through the service every day, whether you log in or not. The day you turn 18 I’m going to know your date of birth.

      • Carl@anarchist.nexus
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        23 hours ago

        I actually just updated my post to clarify how child/teen accounts would be handled without needing direct verification. No hash needed for minors, meaning there is no risk of this. I think we danced around each other while posting, because I saw the notification for your comment as soon as I finalized my edit.

    • LordDaveTheKind@piefed.social
      link
      fedilink
      English
      arrow-up
      2
      ·
      21 hours ago

      Some countries (such as mine, Italy) already release a NFC-enabled ID. We would just need an encrypted authenticator on a mobile phone for scanning the ID and providing a validation code.