The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that authenticate the user against a government. The digital wallet solution is an extension to that system that will allow foreign EU citizens to authenticate themselves more easily (eIDAS 2 already implemented an OIDC-like solution but implementation isn't automatic) as well as offer to store the (often mandatory to carry) ID on your phone.
The "what if you buy alcohol for your kids" sscenario of somone giving someone else their age verification tokens is tired and nonsensical. You can already do that in the real world. We accept that risk and, depending on the country, make it a crime in case they do catch you. It hasn't made liquor stores send someone along to see you drink your booze or watch you enjoy your porn mag.
This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+. This creates a tradeoff where the states would have to essentially roll their own crypto storage and bank on this being safer than simply rotating through batches of signatures generated by the hardware cryptography modules (which is largely unproblematic in the grand scheme of things). The major advantage of using the hardware module is that it makes it much harder for attackers to extract the actual secret should the device ever fall into someone else's hands, something that happens to phones from time to time.
Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives as it already addresses most of the concerns copy-pasted into these threads https://eudi.dev/1.6.0/architecture-and-reference-framework-....
Our focus therefore should be controlling what governments can do with them - for example disallowing blocking/removing someone’s id, just as we should disallow removing citizenship.
Even more reason to make the "demo" app do things correctly because it's very unlikely that all member states actually implement things correctly.
> The internet is scary, parents think they can’t protect their children from many bad things happening, and someone came to provide a “solution."
A simple solution is just not providing your kids with a phone or computer.
Don't forget that many sources of porn will not obey this. Think the pirate bay will ask for age verification? If they obeyed the law they wouldn't even exist.
It's a solution for nothing, as the article points out too.
Also, remote attestation doesn't work that way and for good reason. Under a true ZKP system, a single defector (extracted/leaked/etc key) would be able to generate an infinite number of false attestations without detection.
- If you rely on Big Tech for your identity and data you loose all privacy but can expect some security.
- If you go with your government you still loose your privacy but also all security.
I saw on HN just in the last month that the EU and France got hacked and very sensitive data is now on the Internet.
It's not for digital IDs. It's for surveillance.
Digital IDs are fine (and desired even) if you are only requiring it for GOVERNMENT (same entity that released them) communication. Push for age control is scheme to make that info available for private companies and that's the trojan horse here.
"EU Age Control" is not a Trojan Horse. The software (app) does what it purports to do. No one _wants_ to use it
The "Trojan Horse" is the corporate mobile OS. It's a "free gift". People such as the author happily accept it. These people _want_ to use the corporate mobile OS for what they believe it is, which is something other than software to defeat privacy for the benefit of Google, Apple and their advertiser business partners and customers
People don't think of the software as performing that function. Meanwhile it is the core "business model" of its distributor. The corporate mobile OS is a Trojan Horse
This is why the "age verification" app only works when using the corporate mobile OS. The author states:
"The apps will not work unless you have a Google or Apple approved device. Forget Linux, GrapheneOS, Huawei, after-market firmwares. It's part of the security model."
The bogus justification for requesting ID is not "age verification" it is "security". That's the nonsense reason why the computer owner cannot use an OS he/she compiles himself/herself and why people happily accept the Trojan Horse. The corporate mobile OS is an instrument of data collection, surveillance and online advertising but that's not how the author sees it. He does not see what's inside, he sees a beautiful "free gift"
The question is whether citizens can build enough pressure for such verification systems to be state-based and truly zero-knowledge (akin to the EU's) versus having the private sector 'verify' each user to siphon data, profit off it (Thiel's Persona) and fortify surveillance-capitalism and autocratic administrations.
The fantastic irony is that in some weak attempt to protect against the "evil big tech companies" they directly facilitate increased mass surveillance and removal of individual rights, instead of choosing more scalable and robust answers such as funding and promoting the development of protocols and open standards that can be applied voluntarily and in a decentralized manner to help mitigate these problems.
I have computers side by side on my desktop running Linux, and it is amazing to me how I can call `wormhole send --message hello` and receive it on the machine next to me, knowing that only I can receive this message, without it running through an age approval mechanism, without it being client-side scanned, and without being logged in some government database.
This is the century of AI and robotics - technologies which can facilitate great concentration of power and wealth. Gradually introducing mechanisms that facilitate digital fascism seems like a really bad way to guard us against this.
https://www.nrk.no/norge/datatilsynet-bekymret-for-personver...
Anyone else here planning on blocking sites that require age / ID verification? Are there any publicly available domain deny-lists that could be added to uBlock yet?
Not much more freedom, but the control is outside voters reach.
Just ask Nicolas Guillou
Besides, if someone wants a digital ID, it already exists in many countries. Phones with NFC chips can read many passports, e.g. Germany has an "electronic passport" since 2005. It's barely used, though, because it's bullshit.
As mentioned digital ids are a thing and this is where everything is moving. The author mentions that it would be great to use it but does not believe it is possible and then says age checks will lead to it and it is bad. There are reasons why digital ids will be forced and one of the big ones is because bigtech companies do not want to invest into looking after the content, e.g. misinformation, bullying, etc. Not to mention the inability of companies to control the age of users, and everyone knows this is not in the interest of advertisers.
Criticism is good but it also has to offer some options. Saying everything is bad bad does not help. All in all I have kids and it is very difficult to filter all of their internet traffic and I am not your average parent. Kids are reading crap and get brainwashed everyday, and the idea that you should just let them is ridiculous. Cyber bullying is a thing and I wonder what would you do when your kids get to be on the receiving side.
IMO this is trying to blame politicians who represent their electorate who wants this without acknowledging that the issue is in huge ad funded companies whose interest is to gather all that private data without any supervision or filtering. BTW Data is constantly being leaked from large companies as well, not only gov entities.
In relation to guesstimates the author jumps to possible conclusions without sufficient proof.
What would the author suggest to fix the main issues though?
This shows that the EU commission is systematically lying.
This problem used to exist in the past with Leyen - she is ultimately a lobbyist and that has to stop. Friedrich Merz too by the way - there is a reason why recent polls indicate that the german voters want him out of politics at once.
The EU needs to reform. Right now lobbyists have too much abuse-power. The age sniffing is a great example here - isn't it suspicious how this goes in sync right now in so many countries? Who is paying for this? Nobody needs that, except for some companies.
> Big platforms must verify age for certain content.
But why is their concern, suddenly my concern? I see no need to be in support of any law that would require people to ID in order to access information on the world wide web. That's very obviously the real goal and agenda - everyone with a bit of brains sees this.
> It is the same EU that hates these American corporations and wants EU alternatives for everything
That's not true. The EU commission I consider a lobbyist group, for instance. They lie and lie and lie.
The EU parliament is not much better - you can buy legislation quite easily: https://en.wikipedia.org/wiki/Qatar_corruption_scandal_at_th...
Nothing will seriously changed. The current way how the EU is structure is totally wrong; and it will not be fixed because those in the system, benefit from it financially. See the recent attempt to force EU taxpayers to pay more for those goons. They constantly try to inflate their own budget, at our cost.
> yet no one can make a phone usable for age verification without the blessing of Google
Indeed. We have total incompetence at the leadership level. It should be replaced with technical prowess, but as long as lobbyists such as Leyen are running the show, nothing will change. See the corruption scandals when she was still in Germany. Interestingly the AfD is also full of that, yet voters don't see it - Weidel was working for many years for Goldman sucks. So a next generation of lobbyists will replace the older generation soon. That's why this system how it is, is unfixable. It is broken by design.
We'll need to apply for digital IDs for bots and AI agents?