Stop Killing Drinking: No ID & No Age Verification for buying beer.
We (as a society) recognize narcotics, such as alcohol, as bad, so we ban the children from taking them. We don’t burden the parents, because we recognize that there’re parents who won’t care.
Predatory online platforms are the same. If you don’t want to verify your identity, don’t use them.
If you are forced to be verified (but age verification is not the same as age declaration) without using those services, then it’s a valid compliant.
Honestly I think what is needed here is something similar to TLS: build a chain of trust with multiple “authorities” that can validate your age.
Then we can potentially have open identity issuers that validate age, minimum/no logging, ram servers, periodic power cycles, and independent audits. Assign the cert to an email address or something. Only include age >16/18/21 and a expiry date.
There would be a problem with tracking accounts across services, but if the cert name is only tied to an email, it wouldn’t offer any more tracking info than the email used tied to your online accounts.
Do you know how the implementation proposed by EU works?
How would that be a better solution? It is more complicated, more expansive and I see no benefits with it, in comparision to what the EU proposes
I’ll start off by saying I’m not super familiar with the EU proposal for digital IDs (other than looking at a few articles here and there), but
-
I’m not in the EU. The EU proposal is tied specifically to the EU. And without documents that establish physical presence in the EU it makes it hard to interact with EU services. A cert with an email doesn’t have this problem.
-
There are more problematic cases than “non-EU citizen outside of the EU want to access EU services”. There are always edge cases where there’s a piece of document that establishes the person is legally allowed to be here but is glossed over as an “ID”. Usually, you can present these in person and a human would be able to check it. It’s much harder to convince an automated machine to do so, especially when it isn’t in a drop down list. Which means no digital ID for this person (since the system can’t verify). This is not hypothetical. I have actually encountered this myself outside of the EU. Impossible to submit rental applications, trade-ins at Best buy, rent cloud servers, etc. A verification system backed by multiple non-government entities can alleviate this by 1) only verifying age and 2) verifying age through different methods, sometimes even through human vetting.
-
Data protection is governed by policy in the EU proposal. Policy can change. It’s a lot harder when something is technically impossible by design. A cert with only an email cannot produce a name in it, even if storage was implemented incorrectly.
-
My understanding is that while the digital id wallet is supposed to be open source, currently it depends on Google attestation framework and can’t even work on GraphineOS. You don’t run into this problem with a file.
1 & 2: it would work the same as all other EU specific things. You don’t need to comply with GDPR for people outside EU, you wouldn’t need to verify users outside the EU.
3: I don’t know what you mean. It could be easy to modify spec of those certs to include names.
4 You don’t know how this proposition is supposed to work.
In short:
There’re officially approved apps (you can’t just create you implementation arbitrary, but if you implementation meets all standards, you can work to have it approved). Using those apps, your credentials are secured with one (or many, I don’t understand that part) of:
- Hardware secure element
- Software secure element
- External device
- Server HSM operated by the provider
Those apps must also use some defined encryption standards.
When you create your app, it needs to be approved by one of the member states.
The app can store all kinds of personal governmental things such as your ID, bank account number, drivers license, etc.
When a service wants to know whether you are 18 or more, you can give them your wallet. The wallet app will show who demands what informations and a reason they put in the request. You can approve or reject the request.
It doesn’t have to be tied to google or anyone other.
Yes, those apps won’t be libre, but (and you don’t need to agree with me) in my opinion this is better than letting people create any implementation they want.
GrapheneOS can create thier implementation, that relies on hardware security chip. Linux distros can create a joint implementation reliant on yubikeys and alternatives.
Also, alternatives must remain.
Response to 1: funny thing is that one of the ID verification issues I specifically had is with Hetzner. They need to do a ID verification, recognizes my address is from Country A outside of the EU, so it goes through a Country A specific verification. Then rejects my ID because it’s a rare form of ID in Country A. I also have an ID for Country B but they won’t recognize it with a Country A address.
Response to 2: I’m specifically referring to people residing in the EU for this one. People in the EU that “slip through the gaps” since their ID is somewhat uncommon, thus getting locked out of digital services since they can’t validate and obtain a digital ID easily.
Response to 3: the counterpoint here is network transport protocols, such as TCP and UDP. At this point, it is no longer possible to build new protocols or modify these protocols because of how entrenched the infrastructure hacks surrounding these protocols are, such that no new protocol header would be possible to get through the Internet without it being dropped by middleboxes. I’m suggesting utilizing this technical moat as a feature here: have a simple proposal spread so wide that it becomes almost impossible or economically unfeasible to switch to something invasive.
My issue with 4 is more about current implementation rather than the proposal. So far, the main (or only functional implementation, I’m not sure) is the one that depends on Google attestation. While this could change, I’m not the biggest fan of trusting something to “policy/proposals”. X509 is robust, has key management sorted out, and doesn’t have this specific issue. While anyone can create a cert, that doesn’t mean the cert is useful if it’s not signed by an approved CA.
-
Supported. Next, start a petition to criminalize politicians pushing the same crappy laws again and again in the hopes they at some point pass.
Supported and yes, please.
I’ve heard these encryption backdoor proposals come back every year or two for over the past 2 decades
Well, not exactly, but almost!
This initiative is just a smokescreen; it actually pushes things down the slippery slope.
Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law. The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure
Define “necessary”. Define “by law”. The pushers for proof-of-age already say it’s anonymous – but it can’t be.
Yeah, I was about to “sign” until I had to provide the data which we sign to not have to provide. Great. I mean I get it, but feels weird still
I asked theses questions to the person in charge, and published the response, you can read both questions and answers here : https://lemmy.world/post/51227026/25554402
I find the person’s answer very disturbing and twisted:
The battle that can still be won is over whether using them stays a free choice.
Note how he/she is speaking as if EU was Russia. There’s a regime that governs on us; we can try to fight it. This is not democracy, where the goverment represents the people and the people’s will. Either – very likely – this person has simply accepted (and I don’t know how good such an attitude is) that EU is not a democracy; or they have unclear ideas about democracy.
“Unless strictly necessary, proportionate and provided by law”: this is not our invention and not undefined. It is the limitation test of Article 52(1) of the Charter of Fundamental Rights, the standard the Court of Justice applies to every restriction of fundamental rights.
Well they don’t write that in the initiative’s text. They just say “unless provided by law”. This means that if a law passes that mandates chat control, or age-verification for accessing all internet, then it’s OK with them – it’s provided by law now.I stand corrected, they specify “Articles 7 and 8 of the Charter of Fundamental Rights” in the Annex. But I still think this is poorly written: why not explicitly mentioning the main message of those Articles in the main text? That “unless provided by law” in the main text is extremely ambiguous without the Annex.
I agree it needs to be well defined. But there are government and private services that require identification and uploading selfies and passport pictures onto random websites is worse than a regulated ID service that can provide a trusted API.
There are tons of risks though: data gathering, privacy invasion, censorship, disproportionality…
That’s why I prefer good regulation. One that also defines when it’s “necessary” and when it’s inappropriate to the point of illegal.
Let’s add more conditions: privately owned or managed brings the risk to open up the “service” to more and more websites that don’t need or shouldn’t require your identity. If it has no monetary interests that risk is reduced. Not when you live in an oligarchy though…
do we sign it this way? it would just agree to doing nothing but with fancy words, wouldn’t it?
No, we don’t; it’s exactly as you say. My impression is that this is something organized by the pro-chat-control and pro-age-verification lobbies, to deceive with words people who are against. They get them to sign and then they can say “people signed for this!”.
It’s surely important to spread an anti-misinformation campaign!
Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law.
Are you not aware of the Digital Services Act? This piece of legislation alone, provides all the incentives for service providers to do exactly that; unless they change their business-model, which is rather unlikely. By default, users should be treated as adults and therefore unrestricted in their access; rather than children unless proven otherwise.
If the EU would simply mandate operating systems sold within the jurisdiction, to allow specification of an optional ‘date of birth’ field, which is local and purely on a trust-basis (no external verification required); this should be more than sufficient for signaling an age-bracket to a service, which may then serve an “age-appropriate experience”.
A digital identity wallet should be strictly reserved for matters that already required personal identification. Using such heavy-handed measures for controlling access to adult content, or even social media, is complete and utter overkill. I’m not interested in more empty, technical, server-side “trust me, bro” promises, for something that is fundamentally disproportional.
this should be more than sufficient for signaling an age-bracket to a service, which may then serve an “age-appropriate experience”.
nothing should be signaled to any service. the service should signal its age limit, and the local software needs to compare the limit with the user age. that too could happen on a per content basis, I guess HTML or CSS could be extended with a new property for that.
then, if the user age is below the limit, the browser should continue loading the page as usual, but hidden from the user, to avoid introducing a new vector for fingerprinting.
A digital identity wallet should be strictly reserved for matters that already required personal identification. Using such heavy-handed measures for controlling access to adult content, or even social media, is complete and utter overkill.
or even to government services portals that did not require personal identification.
Everyone don’t forget to Sign, Cross-post, Federate and Share everywhere you can !
In the US, you have a lot of this stuff coming in via the lawsuits against Meta for which so many people here are cheering. For that matter, the EU is also seeing lawsuits of that type.
The US doesn’t need more lawsuits, it needs better regulation.
Déanta ✍️
Fatto ✍️
Signed, but be careful, the website is shitty and does not let you out with the back button.
Signed!
Done, thanks!
Done








