This isn’t so strong on the coding part, but touch in some degree on this regard. The focus is on the data storage and access of data. I hope you like this post.
All feedback is welcome.
This isn’t so strong on the coding part, but touch in some degree on this regard. The focus is on the data storage and access of data. I hope you like this post.
All feedback is welcome.
Removed by mod
Please express disagreement in a less hostile manner when commenting in our communities.
There is a use for age verification. Most people’s problem with is is that 1) the implementations are security and privacy disaster. 2) overzealous application.
Suppose those were not problems - I still wouldn’t want papers please on the internet in principle. “Age” (I.D.) verification online is just a bad attempt at parenting.
I understand the feeling on the dictatorship view of the things.
The problem, in my perspective is that, the wrong set of people (aka.: big tech) already have this data, if not even more than data, or the private surveillance companies (aka.: pala||n%t65||) have this data.
This is where the danger lives. This data can and will be used for profit. To pray on the small guy, to make life of the common worse.
I know that the regime in some countries (like US), trusting the government is hard. But with the right set of audits, encryption and some push from the people. Data can be secure and private store. And only with the permission of the owner of the data provided to the right person, for the right amount of time.
Just to be clear, I know this is mostly wishful thinking, and utopian view.
But we need to start in some point this change.
I trust a government to do some tasks well but there are goals people want which I cannot trust. There is no one who can be trusted to choose what you yourself can read/hear/see. Even though people can die from speech I can’t trust a government to censor it.
Even if companies had good intentions, and put a lot of effort into security, I wouldn’t trust an electronic version connected to a network. Like how I wouldn’t trust a government to do electronic voting.
I don’t know how to to convince people but it seems the only answer - to promote the value of privacy and teach people how to avoid having data on them being collected.
I think I got your point.
But if a system is done in a proper secure way, and does have the proper audits, this won’t be a problem in my humble view.
Voting online does carry a different problem, the anonymity problem. If the vote is open and visible to everyone, online voting carrying a
CitzenID+Hashfrom a user focused device, should be enough. Of course this would still bring other problems(multiple devices for the same person, or old devices trying to mimic a user… there is plenty of problems, mostly a business problem, not a technical one)
We already check for ages when buying alcohol or cigarettes. We USED to do so while buying physical games.
Buying these online should still have the same verification is in person, but we need a better way of doing it.
Usually done with a government issued ID, which wasn’t digital, the moment it is digital how to prevent from being used (the information) without your consent?
Plenty of ways.
The way I would look at is a government portal that a site can send a query to “Is this person over 16?” The site would show you a code that you put into the portal (after logging in) to match that claim to your ID. That way, data is only accessed if you approve its access, the site doesn’t actually know who you are, just that you are over 16, and theoretically, the government doesn’t know who was requesting (although I can see there being issues with spam).
This could probably be improved with a government ID app and some QR codes etc. The problem is that for this to work the Government portal has to be built with a privacy focus, not a spying on you focus.
In my blog post I describe a similar flow for data access that follows similar steps.
Looks like we were thinking on the same path.
I’m not concerned with some random employee looking at an ID card for a few seconds. I don’t trust any proposed online system to do the same. Any government requiring companies use an age system is just asking to dox yourself.
There is no reason that it can’t be done properly though, if it’s done properly it’s not necessarily a bad thing. You can set it up so the company only gets the info they need and the government doesn’t know who is requesting.
It’s very bad for me thanks - I either give up increasing more online communication services or risk punishment for circumventing this bull manure.
If you’re a big company you can afford to do it “properly” (whatever the technologically illiterate goverment chooses). It’s undue burden on any tiny selfhosting personal use or fresh starting competition. Your age is information I don’t want to store - I don’t want to store anything about you I don’t need.
deleted by creator
I agree, on the past I had a proposal that the OS should have a device level API to provide this information, in this case apps and (the browser as an APP) would be able to consume this information from the device. And it’s up to the device manufacturer (or the OS installed) to add a age system.
I not denying that there is holes in this idea. Linux users could simply add a simple form with “I was born 01-01-1900” and everything would continue the same. But on the MicroSlop, Gargle and iPear worlds, they would be able to validate once and keep the information on the device. And each webpage, app and such won’t be able to ingest your personal/private data.
On this post, I do explore little bit this, but I do focus on the idea of storage and access of data.
This, to some extent, already exists as law in the US. In some jurisdictions, the OS must soon request the age from the user and provide it to some applications. It’s not verification though, or at least it’s not required to be.
This started a whole war over systemd even adding a field for it (not a form). If they added a required form, it would probably start WW3.
No thanks. I’m not validating, so I’d be picking up the next Motorola phone with GrapheneOS on it instead.
Edit: to elaborate more, because the phone manufacturer is a third party and most likely sells or otherwise makes available that data to other third parties. It’s also a form of deanonymization through an untrusted party.
Sadly the regime in US is kind of crazy right now. So the trust in the government is degrading, and maybe can be recover in the next decade. But for sure change is needed, on the age verification also.
But I think that age verification should be a device level API, and this follows to the next…
Linux is a unique case, while they are open, flexible and easy to make your own distro, this also implies that a public distro should implement this API, and since this API is on the OS not on Kernel. Which means people fighting, but they can just ignore this API and make it return false to any and every request.
While distros like Ubuntu and maybe Fedora would follow (providing the baseline for the dependent distros), so they can also add a third-party validation layer, which also can be replaced with the government, or a fake one that always says that you are over 99 years old.
Truth to be told, this is a band-aid on the storage and ownership problem, the focus of the post. With the correct layer the OS can keep your “age” with a lease, and you on your phone can use the app to renew the lease whenever you need.
Again, this isn’t a perfect solution, I would even call it a solution since it have so many holes in it. But it’s the point of the conversation.
Hell yeah!
Totally, and with fake API’s to make every page guessing my age wrong! This data sucker can suck my…
Jokes aside, I’m with you on this one, let the OS choose, even if this is just a form with “Birth” field and let the government verification as a different problem.
Like I discussed in the post, the moment you have heavy fines for keeping illegal data, and requires the user to take action to lease the information, we will start to notice how much data these big-tech have on us.
Ps.: Thanks for reading the post and following on the conversation.
That was a little bit agressive. I’ll give you the opportunity to learn from your mistake and discuss what bother you in this blog post.
I refuse to soften my tone. Typical piefed user.
Tagged as Fedposter.
“Please, Daddy government. Come own me.”
No explanation needed. You are willingly rolling out a red carpet for fascist governments. The best way to deal with a fascist is zero tolerance.
Did you read the post?
It’s not that. It’s clearly a distrust (which is also part of the post).
But the problem with trust can be solved with “how to access data”.
Edit.
Since you clearly didn’t read here a snippet
If you don’t trust, that’s fine. This is good. Government should be transparent, and should be auditable. To be honest we have close ideas, and we want the same thing (I guess), privacy and security for our data.
(and keep our data away from datahouses and bigtech)