this post was submitted on 05 Aug 2026
185 points (99.5% liked)

Privacy

50235 readers
337 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] isleepinahammock@lemmy.blahaj.zone 13 points 2 days ago (7 children)

I have a solution to the age verification problem. There is a way to affirmatively prove someone is a real human adult without invasions of privacy. We can use the same ID verification system we've been using for centuries: public notaries.

Governments could hand anonymous cryptographic tokens to notaries. These contain no information on the individual. They're simply a unique cryptographic token. You can go to a notary, pay a nominal fee, show your ID, and grab one of the tokens (possibly just a code printed on a card) from a large bin of them. You can then use this token to register for any number of sites. The notary themselves does not need to note which cryptographic token you grab. The notary doesn't even know what token you received. The goal is merely to prove you're an adult human, not to create a cryptographic key tied to your specific identity.

I would then let people do this as many times as they want. You can get a hundred such IDs. They wouldn't cost much, a few dollar or Euros. This would be no barrier to individuals accessing the net, but it would make them unsuitable for mass spamming.

[–] NewNewAugustEast@lemmy.zip 5 points 1 day ago* (last edited 1 day ago) (1 children)

No. There is zero need for this shit, don't normalize it.

[–] isleepinahammock@lemmy.blahaj.zone 0 points 1 day ago (1 children)

There is a clear need for it. There's value in having online discussion spaces that aren't just swamped with bots. We really need a reliable way of telling human from bot. I want to find a way to do that preserves privacy to the greatest degree possible.

Do you have any constructive criticism to offer? Maybe a suggested improvement, or an alternative way to accomplish the same goal? What's your solution to separate human from bot?

[–] NewNewAugustEast@lemmy.zip 4 points 1 day ago* (last edited 1 day ago) (1 children)

There is no need for it. Sorry. Certainly not government mandated, which is the worst part.

Frankly if you treat the internet like was did all the way back in bbs days, it doesn't matter that much: Everyone is a liar. So I don't care what anyone says. Bot or not.

In the forums I run we haven't seen much of a bot presence at all, so these spaces already exist. How do I know? We have all met each other at one point or another. So I may know a, a knows b, and so on.

Do I want the burden of starting authentication on top of this? No.

I don't want the internet to require me to get authentication. I really don't care about the bot issue. Go outside and meet people in real life if that's what you want.

[–] isleepinahammock@lemmy.blahaj.zone 0 points 1 day ago (1 children)

There is no need for it. Sorry. Certainly not government mandated, which is the worst part.

YOU have no need of it. You're projecting your experiences onto everyone else. Maybe you're content only hanging out in limited forums where you have to know someone to join. And those forums can continue to operate without any human verification. If you don't care whether the spaces you occupy are infested with bots, or can manage with white lists, fine. But most people don't want to talk to bots. Not everyone has the social connections you do.

I don't support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn't mean no one does. Not everyone uses the internet the same way you do.

"Only join forums where you personally know the people there" is not a scalable solution to this problem.

Respect a diversity of viewpoints and experiences. Your way is not the only way.

[–] NewNewAugustEast@lemmy.zip 3 points 1 day ago* (last edited 1 day ago)

You’re projecting your experiences onto everyone else.

In fairness, you are doing this right now.

I don’t support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn’t mean no one does. Not everyone uses the internet the same way you do.

You are free to create websites that function this way, or participate in websites that function this way, but don't push it on the rest of the internet.

“Only join forums where you personally know the people there” is not a scalable solution to this problem.

Sure it is. We didnt all know each other personally when we started, and people are welcome to join anytime. We just can figure out pretty quickly who is real and who is not because we meet each other. So what problem?

Not everyone uses the internet the same way you do.

Of course not, because they are either idiots, or never learned the basics. This is internet 101.

  1. Everyone is a liar.
  2. Everyone is anonymous
  3. Because of rule 2, see rule one.

You are commenting in a privacy forum. I quite likely am talking to a bot, or you are talking to a bot right? So don't listen to me, BUT: no matter how hard you try, making any system that requires any kind of verification on an internet wide scale WILL be abused.

Use the internet as intended and the problem goes away.

Edit: also, even if you filter the bots, the issues remain because in many ways people are just as bad. Misleading, argumentative, liars, agendas, half truths, etc. So it doesnt really matter.

[–] VanRado@lemmy.world 5 points 1 day ago

But then how are you supposed to surveil citizens?

[–] heartSagan5@lemmy.zip 1 points 1 day ago* (last edited 1 day ago)

It’s all silly because computers are not paired with any specific body. You could toss your “18+ accessible phone” to your kid, etc.

Unless they do implants, which is nightmare land because we know they’ll want more than just your birthday.

[–] Zerush@lemmy.ml 1 points 1 day ago* (last edited 1 day ago)

I didn't like the age verification law either, but as it would be introduced everywhere, yes or yes, at least it's mandatory to search an privacy protecting methode, which isn'y not so easy, Because of this I asked Sketchapedia, which shows an zero knowledge system, the service provider only receive an OK or Not OK with it.

In problems which I can't avoid, I always prefer to search solutions or at least workarrounds to fix it.

[–] thanksforreading@lemmy.ml 2 points 1 day ago (1 children)

It would only work if the law mandated that this token cannot be stored or tracked across the web.

[–] bilb@lemmy.ml 2 points 1 day ago (1 children)

I think the idea is that you can use different tokens for each thing.

[–] thanksforreading@lemmy.ml 1 points 19 hours ago

Right but people won't and if you do they can still track you by combining other metadata

[–] FineCoatMummy@sh.itjust.works 5 points 2 days ago

It's a legit idea, and there's a thing like that, called Zero Knowledge Proofs (ZKP).

IMO it's possible in theory. Like set up and managed in good faith, it can work mathematically, and you can prove it does.

My worry tho is that it wouldn't be in good faith. It'll be corrupted somehow. Or it turns out that enough other signals leak that it isn't very effective. Like fingerprinting and stylometry and w/e allow ID'ing despite the ZKP layer.

[–] Cricket@lemmy.zip 3 points 2 days ago (1 children)

Maybe I missed something, but with your proposed solution, what would stop someone from just handing the adult cryptographic token to a kid? It sounds like it would be a similar situation to or even easier to do than fake ID cards or adults buying alcohol for underage people.

[–] isleepinahammock@lemmy.blahaj.zone 5 points 2 days ago* (last edited 2 days ago) (2 children)

Nothing. Who says a solution has to be perfect? If "good enough" is good enough for handling the sale of alcohol, it can certainly be good enough for accessing web sites. No solution to any problem is perfect. You always have to find a balance between preventing the thing you want to stop and the negative effects of your efforts to prevent that thing.

[–] AnyOldName3@lemmy.world 1 points 1 day ago (1 children)

It's not as good as the solution for alcohol as one bottle of beer making it to a child gets used up after only giving one child one drink. Once a token leaks, it can be shared again and again and used by arbitrarily many children arbitrarily many times until someone notices that it's leaked and revokes it (which then means that websites need to actively update a list of revoked tokens instead of just relying on public key cryptography to confirm it was signed by one of a few authorities, or all tokens will need to expire automatically after a short time).

[–] isleepinahammock@lemmy.blahaj.zone 1 points 1 day ago (1 children)

That will always be the case for online age verification. There's nothing preventing an adult from signing up for an account and then just giving the account to a kid. This is true no matter the verification method chosen. Unless you're going to demand people scan their face every time they log in, and even then there are ways around it.

My goal is not to create a perfect solution. My goal is to create a good-enough solution that is as reliable as face or ID scanning, but without the privacy violations.

[–] AnyOldName3@lemmy.world 1 points 16 hours ago

And face/id scanning aren't as good as the solution that works in the real world for alcohol because they can be tricked by a video game face or a photo of someone else's real ID. Any solution that works online can either be trivially bypassed or adds an unacceptable level of hassle and risk (e.g. leaks being used for blackmail) for legitimate users.

The solution for alcohol works really well because very few children have the ability to get a fake ID or convince people it's real and theirs until they're close enough to legal age that it doesn't really matter much if they drink, and parents have the ability to override it on a per-drink basis if they're okay with children drinking under their supervision, while non-parents can only operate on a very small scale before they risk getting caught. Once people are old enough that they're obviously adults, they don't get asked for ID anymore, so it's only a small fraction of the population that have to deal with any hassle, and a shopkeeper can't memorise every single ID card they've ever seen and then suffer a cyberattack and reveal what alcohol specific people have bought to someone who'll threaten all of them in case some of them are willing to pay to have it kept secret.

Preserving privacy means tokens become trivial to share, and then there's nothing stopping a ten year old watching huge amounts of extreme porn except for things that would have worked without having any system, like having their parent stand behind them. If the new system doesn't improve things compared to having no system, then there's no point making it.

[–] Cricket@lemmy.zip 1 points 2 days ago

In that case, I suppose I agree with your solution.