https://digst.dk/it-loesninger/den-digitale-identitetstegneb...
The difference is meaningful. It's mostly prisoners dilemma. If only one persons porn habit is available thats bad for them. If everyones (legal) porn habits are available, then it gets normalized.
The problem isn't my peers, it's the people in power and how many of them lack any scruples.
this is too narrow a view on the issue. the problem isn't that a colleague, acquaintance, neighbor, or government employee is going to snoop through your data. the problem is that once any government has everyone's data, they will feed it to PRISM-esque systems and use it to accurately model the population, granting the power to predict and shape future events.
Briefly, when the ID provider issues the ID it gets cryptographically bound to your phone. When you use the ID to prove something to a site (age, citizenship, etc) the is done by using a zero-knowledge proof based protocol that allows your phone to prove to the site (1) that you have an ID issued by your ID provider, (2) that ID is bound to your phone, (3) the phone is unlocked, and (4) the thing you are claiming (age, citizenship, etc) matches what the ID says. This protocol does not convey any other information from or about your ID to the site.
Otherwise a single person could donate their ID card and let everyone else authenticate with it.
Now you might counter and say it would be enough to give each card a sequential number independent of the person's identity, but then you run into another problem. Each service might accept each card only once, but there are many services out there, so having a few thousand donations could be enough to cover exactly the niche sites that you don't want kids to see.
There is no way to implement this without a complete authoritarian lockdown of everything. There will always be people slipping past the cracks. This means all this will ever amount to is harm reduction, but nobody is selling it on that platform. Nobody is saying that they are okay with imperfect compromises.
And before anyone asserts that the phone can be anonymous, that doesn't work, otherwise you can just have an app that claims to have a verified ID attached.
the social media platforms already measure more than enough signals to understand a users likely age. they could be required by law to do something about it
It seems to me like it's either a privacy disaster waiting to happen (if not required) or everyone but the biggest players throwing out a lot of bathwater with very little baby by simply not accepting Danish users (if required).
The wording on the page also makes it sound like their threat model doesn't include themselves as a potential threat actor. I absolutely wouldn't want to reveal my complete identity to just anyone requesting it, which the digital ID solution seems to have covered, but I also don't want the issuer of the age attestation to know anything about my browsing habits, which the description doesn't address.
The biggest players in social media are precisely the ones that this law is targeting.
No one in charge of implementing this law is going to care whether some Mastodon server implements a special auth solution for Danish users or not, they are going to care that Facebook, TikTok, Instagram, etc. do so.
And if that little Mastodon server ends up hosting some content that is embarrassing or offensive to the Danish authorities, laws like this will surely not be used to retaliate...
Arbitrarily and selectively enforced laws seem like an obviously bad thing to me. If the government can nail me for anything, even if they practically don't, I'll be very wary of offending or embarrassing the government.
The law will obviously be framed in such a way as to hit the targets it is supposed to hit, avoid collateral damage. It's not like complete amateurs are writing our laws.
I responded by explaining why that wouldn't be a good thing.
Have you changed your mind on that point or are you simply not keeping track of your argument? Either way there can't be an honest discussion whether you have the memory of a goldfish or are deliberately ignoring what you've said.
Why would they, though, if "no one in charge of implementing this law is going to care whether some Mastodon server implements a special auth solution for Danish users or not"? The EU CSAR proposal (which Denmark seem very much on board with) doesn't make such exceptions, so why should this law?
> A law isn't a headline on Hacker News, it's a carefully written document.
This is a non sequitur, and also pure speculation.
i think it'll get to: "these methods aren't good enough, we'll have to enforce digital id".
The platforms asks your government if you're old enough. You identify yourself to your government. Your government responds to the question with a single Boolean.
It would be possible for them to provide an open-source app, but design the cryptography in such a way that you couldn't deploy it anyway. That would make it rather pointless.
I too hope they design that into the system, which the danish authorities unfortunately don't have a good track record of doing.
If the app is open source, what stops someone from modifying it to always claim the user is over 18 without an ID?
And using someone else's Id and password is the same as every method of auth
Source: I wrote Digitaliseringsstyrelsen in Denmark where this solution will be implemented next year as a pilot, and they confirm that the truly anonymous solution will not be offered on other platforms.
Digitaliseringsstyrelsen and EU is truly, utterly fucking us all over by locking us in to the trusted competing platforms offered by the current American duopoly on the smartphone market.
There is nothing more permanent than a temporary solution.
Same people now: how will the poor company know that it's an underage user?? Oh noes!