Daniël

@danieldk@mastodon.social

Perfil original

@EUCommission This is great, but misses the forest for the trees:

* Google is rapidly closing Android by making it harder to install apps from outside the Play Store.
* Google is rapidly closing Android by limiting AOSP to two drops (main release, QPR2) a year.
* Google makes it harder for alternative systems by putting a 3 month embargo on security patches, which they only give to OEMs.
* Google forces competitors out of the market with Play Integrity.

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.

Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.

@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.

Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.

We're talking about very different systems. In Spain, for the past 82 years, all citizens have had an official identity document issued by the state. This document contains an electronic certificate that allows us to identify ourselves online to government agencies. With this type of infrastructure, a neutral state point is viable, one that simply certifies and responds with true or false to the legal requirements of any particular online service. The online service does not receive any other information than the complaining (or not) of the person on the other side of the connection with law requirements. No other data have to be shown or saved.

I don't see the connection with free software because I'm not aware of any legal restrictions on using free software repositories by underage, and I cannot imagine it as a political possibility.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen

You are missing my first point, even if an age attestation method does not reveal the birth date, you can infer the birth date from it because some day the attestation will flip from 'false' to 'true'.

Second, Spain is piloting the EUDI Wallet for age verification, which will implement remote attestation:

github.com/eu-digital-identity

@david @bjoreman @HennaVirkkunen On the point of using identity documents directly: either you have to send the signed attestation to the site/app for verification, which would deanonymize you; or some gatekeeper like a government site would have to do it and give the result to a site/app and in that case the gatekeeper knows what apps/sites you are using, which is a huge privacy invasion. Also doesn't protect well against a kid using someone else's ID to verify, so it's mostly security theater.

From a technical standpoint, if you want to restrict access to a website based on some form of identity data, you either trust the web providers or you trust the state. If the state legally prohibits itself from recording which sites you visited or even how many times you used the service, the issue should be settled. If, for whatever reason, even reasons of principle, the state is deemed untrustworthy, then the issue has no technical solution because it is fundamentally a political one.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu
Excuse me Daniël, but I don't understand the problem. Wasn't the goal to prevent people under the legal age from accessing the service? Once that was achieved, what's the failure?

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.

Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.

@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.

Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.

We're talking about very different systems. In Spain, for the past 82 years, all citizens have had an official identity document issued by the state. This document contains an electronic certificate that allows us to identify ourselves online to government agencies. With this type of infrastructure, a neutral state point is viable, one that simply certifies and responds with true or false to the legal requirements of any particular online service. The online service does not receive any other information than the complaining (or not) of the person on the other side of the connection with law requirements. No other data have to be shown or saved.

I don't see the connection with free software because I'm not aware of any legal restrictions on using free software repositories by underage, and I cannot imagine it as a political possibility.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen

You are missing my first point, even if an age attestation method does not reveal the birth date, you can infer the birth date from it because some day the attestation will flip from 'false' to 'true'.

Second, Spain is piloting the EUDI Wallet for age verification, which will implement remote attestation:

github.com/eu-digital-identity

@david @bjoreman @HennaVirkkunen On the point of using identity documents directly: either you have to send the signed attestation to the site/app for verification, which would deanonymize you; or some gatekeeper like a government site would have to do it and give the result to a site/app and in that case the gatekeeper knows what apps/sites you are using, which is a huge privacy invasion. Also doesn't protect well against a kid using someone else's ID to verify, so it's mostly security theater.

@david @bjoreman @HennaVirkkunen that site somehow doesn't seem to work here. But in general, these proposals fail, because sites can regularly probe for age brackets. If you do this on a regular basis, you can figure out someone's birthday.

E.g. if 12 years is a bracket boundary, the day that age gets attested is the birthday of the kid. Even more likely because someone is more likely to check close after their birthday to unlock some site/functionality.

Excuse me Daniël, but I don't understand the problem. Wasn't the goal to prevent people under the legal age from accessing the service? Once that was achieved, what's the failure?

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.

Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.

@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.

Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.

We're talking about very different systems. In Spain, for the past 82 years, all citizens have had an official identity document issued by the state. This document contains an electronic certificate that allows us to identify ourselves online to government agencies. With this type of infrastructure, a neutral state point is viable, one that simply certifies and responds with true or false to the legal requirements of any particular online service. The online service does not receive any other information than the complaining (or not) of the person on the other side of the connection with law requirements. No other data have to be shown or saved.

I don't see the connection with free software because I'm not aware of any legal restrictions on using free software repositories by underage, and I cannot imagine it as a political possibility.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@HennaVirkkunen How is that to be done without handing these platforms our identities and ability to track us? Seems the last thing I want is for them to be trusted with anything.

There is a simple way: the EU establishes a «neutral point of identity» similar to the passage of Spanish administration https://pasarela.clave.gob.es/. Just the regulation enabling it have to make sure it doesn't store data on which sites you visit.

This service only has to respond to the provider's request affirmatively or negatively given legal conditions to access its site.

CC: @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen that site somehow doesn't seem to work here. But in general, these proposals fail, because sites can regularly probe for age brackets. If you do this on a regular basis, you can figure out someone's birthday.

E.g. if 12 years is a bracket boundary, the day that age gets attested is the birthday of the kid. Even more likely because someone is more likely to check close after their birthday to unlock some site/functionality.

Excuse me Daniël, but I don't understand the problem. Wasn't the goal to prevent people under the legal age from accessing the service? Once that was achieved, what's the failure?

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.

Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.

H

We say this loud and clear: online platforms are responsible for protecting minors, and they need to do more to deliver on this responsibility.

The full press releases:

🔗 ec.europa.eu/commission/pressc
🔗 ec.europa.eu/commission/pressc

@HennaVirkkunen How is that to be done without handing these platforms our identities and ability to track us? Seems the last thing I want is for them to be trusted with anything.

There is a simple way: the EU establishes a «neutral point of identity» similar to the passage of Spanish administration https://pasarela.clave.gob.es/. Just the regulation enabling it have to make sure it doesn't store data on which sites you visit.

This service only has to respond to the provider's request affirmatively or negatively given legal conditions to access its site.

CC: @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen that site somehow doesn't seem to work here. But in general, these proposals fail, because sites can regularly probe for age brackets. If you do this on a regular basis, you can figure out someone's birthday.

E.g. if 12 years is a bracket boundary, the day that age gets attested is the birthday of the kid. Even more likely because someone is more likely to check close after their birthday to unlock some site/functionality.

Excuse me Daniël, but I don't understand the problem. Wasn't the goal to prevent people under the legal age from accessing the service? Once that was achieved, what's the failure?

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.

Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.

H

@HennaVirkkunen I think officials should re-examine the unspoken assumption that small children must be hooked up to whatever remote computers.

Car analogies work well in this area. If the Internet is the "information superhighway", then why are parents expecting little Johnny and Susan to play out on the highway? Just a generation ago it would have been framed as abuse and neglect, but now our children must somehow be steeped in the SV wizardry or else they will wither on the vine...?

H

Keeping kids safe online is a top priority.

Today, the Commission has preliminarily found porn platforms Pornhub, Stripchat, XNXX, and XVideos in breach of the Digital Services Act for allowing minors to access adult content.

We’ve also launched investigation into Snapchat under doubts that the platform has failed to adequately protect minors from harmful content, grooming, and illegal products like drugs and vapes. We also suspect that they have failed to verify users age sufficiently.

H

We say this loud and clear: online platforms are responsible for protecting minors, and they need to do more to deliver on this responsibility.

The full press releases:

🔗 ec.europa.eu/commission/pressc
🔗 ec.europa.eu/commission/pressc

@HennaVirkkunen How is that to be done without handing these platforms our identities and ability to track us? Seems the last thing I want is for them to be trusted with anything.

There is a simple way: the EU establishes a «neutral point of identity» similar to the passage of Spanish administration https://pasarela.clave.gob.es/. Just the regulation enabling it have to make sure it doesn't store data on which sites you visit.

This service only has to respond to the provider's request affirmatively or negatively given legal conditions to access its site.

CC: @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen that site somehow doesn't seem to work here. But in general, these proposals fail, because sites can regularly probe for age brackets. If you do this on a regular basis, you can figure out someone's birthday.

E.g. if 12 years is a bracket boundary, the day that age gets attested is the birthday of the kid. Even more likely because someone is more likely to check close after their birthday to unlock some site/functionality.

Excuse me Daniël, but I don't understand the problem. Wasn't the goal to prevent people under the legal age from accessing the service? Once that was achieved, what's the failure?

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.

This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).

@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.

@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.

Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.

Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.

H

@HennaVirkkunen I think officials should re-examine the unspoken assumption that small children must be hooked up to whatever remote computers.

Car analogies work well in this area. If the Internet is the "information superhighway", then why are parents expecting little Johnny and Susan to play out on the highway? Just a generation ago it would have been framed as abuse and neglect, but now our children must somehow be steeped in the SV wizardry or else they will wither on the vine...?

H

Dear @EUCommission and @HennaVirkkunen
Please consider what the world wide community of scientists for computer security and privacy, who are studying the impacts of technology on society, have to say on this topic. They published an open letter, signed by more than 400 scientists in the field, calling for a (temporary) moratorium on age verification online earlier this month:
csa-scientist-open-letter.org/

H

@HennaVirkkunen I understand all the concerns here, but do we realy want minors to grow up watching 5 dudes in a group r*pe like scene do a young underaged looking woman with pain in her face, urinating on her, thinking that's normal and they have to do or accept this in their later lifes?

Those are contents minors find behind these companies "Are you 18 years old? Klick yes or no!".

This is irresponsible!

Forcing consumers to reveal their identity to data abusers keeps no one safe, not children, not adults. Breaking and bypassing privacy technology actively makes the Internet less safe. Curtail data brokers and abusive targeted ad industry, regulate and monitor what GDPR already legislated.
@HennaVirkkunen

H

@HennaVirkkunen How do you suggest the platforms should do that? The lazy way everybody around pushes results in the platforms storing huge ammouts of data with government issued IDs. If you don't trust them with child protection, do you really trust them to keep that data private, not leak them and not misuse them?

So please, really think through the next steps. Cause so far I see only really stupid solutions for this issue, resulting in weakening privacy in the name of protecting children.

H

@HennaVirkkunen how exactly these platforms should identify minors? And what would prevent minors from using a VPN to connect from a country that doesn't put such restrictions? Also, let's say you target the big players and VPNs are not a thing: how much time does it take to people to migrate to other less known porn sites, potentially being exposed to higher risks (e.g. viruses)?

H

@HennaVirkkunen

Are you suggesting it would be safe for EU citizens to submit their passport details to services like PornHub?

I think the sentiment is good but for age verification to work it needs to be provided as a service on EU/local governmental level to not leak sensitive information.

Unfortunatly not all countries have the faith in their goverment the same way we in Finland have, and in some cases for good reason, so age verification will be tricky to implement.

@EUCommission If you *really* care about open source, please end Google's use of remote attestation (through Play Integrity) to push open source competitors out of the market.

I can understand that banks and governments want remote attestation, but it should be open to all players, not Google, nor a company cartel.