I don't know the specifics, but seems very reasonable if implemented matches the promise. If it's required also for some non porn sites (social media? gambling maybe), there should be no stigma attached either.
I don't know the specifics, but seems very reasonable if implemented matches the promise. If it's required also for some non porn sites (social media? gambling maybe), there should be no stigma attached either.
They question the quality of the Zero Knowledge Proofs (something like "it's still new") and raise what I find the more interesting question: "who will be left out?". Not only for porn, that is.
Much of the Secure Boot crap could have been avoided if all devices had been required to have a user-accessible mode that trusted a must-issue signer of last resort, and that signer was broadly available.
E.g. LetsEncrypt for devices
If on the one hand we want to improve security via encryption/verfication, then on the other hand we must remove the governments' and corporations' abilities to abuse it.
I'm asking because even oauth would make this kind of attack vector impossible, as the referrer and redirect urls are verified - and I sincerely doubt they're so incompetent not to do something similar in such a context.
There are a lot of verification platforms, so the idea is that the user is asked to be verified and that his proof of identity is reused in live for something else. In the addressbar, user sees "dangerousporn.com" -> "safeidentify.com"
The operator of "dangerousporn.com" starts (manually) an application to a [bank account / crypto exchange "bank.com"], using a fixed residential proxy (Luminati / Oxylabs, etc).
Once a victim arrives on "safeidentify.com", the user that is on "safeidentify.com" is asked to follow the actions that "bank.com" is asking to do (upload your ID, turn head left, turn head right, up, down).
"safeidentify.com" plays back the recorded video on the KYC platform of "bank.com" using an emulated Webcam.
Difficult ? Yes and no, but manually doable on a case-by-case basis, and you don't need thousands of victims as it is really worth.
but ignoring that: none of what youve written there has been enabled by an identity provider hosted by the state. These scams already exists, today and various "special" users fall victim to them.
but lets ignore that too: these verifications are usually done interactively and cannot simply be played back, as you need to actually react to the actions of the person verifying your identiy
but lets ignore that too: its _highly_ unlikely the service will make users upload IDs and get verified via video etc on every connection. I'm gonna bet this is a one-time action, and after that you'll probably have to simply authenticate via 2-3 factors (username, password, biometric, sms, email, e-pass, certificate etc) - so what you're insinuating (this service makes people numb to such situation) is implausible. Especially in the context this scenario is in: merely verifying >18 yo
yes it's exactly the point, use porn websites as a hook to convince the user to do your actions to verify their "identity"
Because it's easy to say "just use that third-party service" but if the cost of that service is well above the profit margin of a porn site, the site cannot really do it.
Then you pass this token to your porn website and they can verify that this token means that you have the required age. But the porn website cannot identify you.
Not sure about the price of such a service, but it would be paid by the public.
> Use an age verification provider that is legally and technically independent of any online platform hosting or providing porn content - https://www.yoti.com/blog/france-age-verification-law-adult-...
So, could be a government website, but likely for-profit companies will try to capture it by any means necessary, the very least a lot of lobbying.
Or for the benefit of the children who have a harder time accessing the porn sites, maybe?
There are minimal privacy implications; it could also be applied to privacy laws and the like protecting minors; it would be trivial for sites to comply.
> the porn site receives only a yes-or-no confirmation that the user is of legal age
What does the external service receive?
If the law forces down people's throats an intermediary between them and a porn site, then it better also force the intermediary to guarantee anonymity.
Hmm...
> But I asked what is that external provider actually receiving.
Sure, I don't know. What I'm saying is that at least it seems possible to make is reasonably private. That's better than if it was impossible, e.g. putting a backdoor in E2EE "only for the good guys". But then I would be contradicting your statement that "there are always ways", so... well.
No amount of cryptography can protect against this. Now, if the French government issued tokens preemptively to everyone, that would work, but then it becomes trivial for to copy the tokens.
Sure, if you start with convenient assumptions, it's easy to prove your point :-).
Now let's imagine that people don't need a token for each session but to create an account. Suddenly they are not asking for tokens after midnight, and not repeatedly, right?
Let's push it as far as saying that other websites may need verification, e.g. social media. And for the sake of the argument, let's imagine that there are more than one social media. If the token issuer receives 4 requests from the same person, is it for 4 social media? 2 social media and 2 porn sites? Not so clear anymore.
Finally, let's pair it with an "eID" app. So people get the app to use an electronic ID (which is presumably useful for things that are not porn). Let's say that when you install the app, it gets 5 age tokens for you. You may or may not use them, it just creates them. Now the token issuer sees that everybody gets 5 tokens. Difficult to say that they all need to access 5 porn websites, isn't it?
I don't know if age verification is fundamentally a good thing. But "no amount of cryptography can protect against this"... I don't know.
> that would work, but then it becomes trivial for to copy the tokens.
Anyway it is trivial for a child to ask their parent to give them access to porn. The whole idea is that usually, parents won't do it.
Of course, understanding that requires a fair bit of technological knowledge.
I imagine most people, when visiting a porn site for the first time and asked to verify their age, if sent to a process that asks them to upload their ID or show their face on camera will simply refuse to do so - regardless of any assurances as to privacy.
This seems to have happened when Louisiana started requiring age verification - driving people, both children and adults, to sites that don't comply with the law, proxy servers, VPNs or Tor. I doubt it'll be any different in France.
I think the whole point of the "eID" would be that people don't have to do that. Using Zero Knowledge Proof.
In France's case though (from the article):
> Instead, users must verify their age using a credit card or a government-issued ID. This check must be carried out by an external service, not the porn site itself.
The whole question is: is it possible to prove your age to a pornsite without exposing your identity to said pornsite and without telling your government that you use it? And that would be the point of Zero Knowledge Proofs.
Now of course, there are infinitely many poor ways to verify the age.