@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.
This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).
@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.
@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.
Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.
Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.
@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.
Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.
@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.
Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.
I don't see the connection with free software because I'm not aware of any legal restrictions on using free software repositories by underage, and I cannot imagine it as a political possibility.
CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu
@david @bjoreman @HennaVirkkunen
You are missing my first point, even if an age attestation method does not reveal the birth date, you can infer the birth date from it because some day the attestation will flip from 'false' to 'true'.
Second, Spain is piloting the EUDI Wallet for age verification, which will implement remote attestation:
@david @bjoreman @HennaVirkkunen On the point of using identity documents directly: either you have to send the signed attestation to the site/app for verification, which would deanonymize you; or some gatekeeper like a government site would have to do it and give the result to a site/app and in that case the gatekeeper knows what apps/sites you are using, which is a huge privacy invasion. Also doesn't protect well against a kid using someone else's ID to verify, so it's mostly security theater.
@david @bjoreman @HennaVirkkunen At any rate, Mastodon is too short a format to go into the details of issues with ZKPs for age attestation, so some useful pointers:
CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu
@danieldk @david @HennaVirkkunen Yeah, it’s not like there are no tools today for parents to control what kids can access.