Stop Killing The Internet: No Digital ID & No Age Verification | European Citizens' Initiative (citizens-initiative.europa.eu)
from taco_shale032@lemmy.ml to privacy@lemmy.ml on 29 Aug 01:19
https://lemmy.ml/post/52003644

cross-posted from: piefed.zip/…/stop-killing-the-internet-no-digital…

#privacy

threaded - newest

pglpm@lemmy.ca on 29 Aug 08:06 collapse

This initiative is just a smokescreen; it actually pushes things down the slippery slope.

Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law. The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure

Define “necessary”. Define “by law”. The pushers for proof-of-age already say it’s anonymous – but it can’t be.

Lemmchen@feddit.org on 29 Aug 11:10 next collapse

but it can’t be

Not true. You can absolutely implement a boolean true/false function on an ID card. German IDs already have that. All you need is a compatible reader (future versions will work over NFC afaik).

asdfasdfasdf@lemmy.world on 29 Aug 19:21 collapse

How do you trust that it isn’t sending identifiable info to them too? Is the software open source and auditable? Is it legally enforced that every hardware uses the open source software?

I assume that it would need some kind of asymmetric encryption signature on the boolean too, and make it change all the time like OTP? Otherwise I’d think it could be intercepted and forged, right?

And how would the reader work? Everyone needs to buy a reader to beep their ID to when they want to watch porn?

unwarlikeExtortion@lemmy.ml on 30 Aug 00:34 collapse

And how do you verify the source of the “yes/no” signal is a valid ID card? How do you know it’s used by the person linked to it?

Either the yes/no is trivially faked (so you might as well skip the formality), or the user secretly does get ID’d.

RheumatoidArthritis@mander.xyz on 31 Aug 07:03 next collapse

It’s a smard card, there’s no reason why the “yes” can’t be cryptographically signed with a government-approved certificate.

That being said, fuck age verification online.

DieserTypMatthias@lemmy.ml on 31 Aug 08:14 collapse

The data live on your eID, which is basically a Yubikey except you can’t save whatever you want on it.

<img alt="" src="https://lemmy.ml/pictrs/image/8e80608a-df8e-41e9-90cd-f6f11347b0c1.png">

Original page, since I don’t want to paste the full translation: meid.minv.sk/?page=frequent-questions%2F#howItWor…


Some countries in the EU like Slovakia also allow you to use passkeys that basically act as supplement to using physical ID card, so that you can use something better like Yubikeys or save it to your password manager.

hneerqe@lemmy.world on 29 Aug 18:34 collapse

While good intended these actions just further validate their ideas, by showing anything other than an uncompromising “No”.