Fuck EU.
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
Well, in that case, fuck you too.
The EU is the only organization that fairly consistently tries to do the tight thing. Its the only organization from which I regularly hear good news. Just because sometimes they make mid steps doesn't mean they're the devil. World wide, it currently is the best we have.
This age verification shit is literallyhappening everywhere, so dunking on the EU for also doing it is disingenuous at best. That they require hardware attestation for that is more a "if you do something, do it well", so in this case "if you do something stupid, do it very well"
Just to be clear: fuck everything about this, but I'm not so small minded to throw the entire idea of the EU off a cliff just because they do something stupid
Edit: this goes without even talking about how without the EU, Russia would simply start picking off state after state because fuck genocide Putin
The Linux + open source community has more potential to be a historic force than the Eurasian Peninsula, and all first world socialists combined. One will be erased, replaced, the better one consumed and made use of.
I am not joking btw
I am not joking btw
Just being ever so slightly delusional if you think that developers are the same as the EU
It's a totalitarian move aimed only at establishing a police state for the average people. It will not affect the criminals or terrorists in the least. They've managed to figure out how to operate without cell phone tracking apparently. Seems the gadgetcops need to figure out how to do real police work again. I'm sure a few guys in their 60s-80s might remember how it was done before the gadgets showed up
Also fuck absolutely every politician who focuses on "supporting" incompetent parents... All this does is to allow them to become even more incompetent and then the government has to do even more parenting...
Gee. I totally not saw that coming.
These people who push for it are fascists, and the only way to deal with fascists is to kill them before they murder you.
bingo bango
I have a solution to the age verification problem. There is a way to affirmatively prove someone is a real human adult without invasions of privacy. We can use the same ID verification system we've been using for centuries: public notaries.
Governments could hand anonymous cryptographic tokens to notaries. These contain no information on the individual. They're simply a unique cryptographic token. You can go to a notary, pay a nominal fee, show your ID, and grab one of the tokens (possibly just a code printed on a card) from a large bin of them. You can then use this token to register for any number of sites. The notary themselves does not need to note which cryptographic token you grab. The notary doesn't even know what token you received. The goal is merely to prove you're an adult human, not to create a cryptographic key tied to your specific identity.
I would then let people do this as many times as they want. You can get a hundred such IDs. They wouldn't cost much, a few dollar or Euros. This would be no barrier to individuals accessing the net, but it would make them unsuitable for mass spamming.
It’s all silly because computers are not paired with any specific body. You could toss your “18+ accessible phone” to your kid, etc.
Unless they do implants, which is nightmare land because we know they’ll want more than just your birthday.
I didn't like the age verification law either, but as it would be introduced everywhere, yes or yes, at least it's mandatory to search an privacy protecting methode, which isn'y not so easy, Because of this I asked Sketchapedia, which shows an zero knowledge system, the service provider only receive an OK or Not OK with it.

In problems which I can't avoid, I always prefer to search solutions or at least workarrounds to fix it.
No. There is zero need for this shit, don't normalize it.
There is a clear need for it. There's value in having online discussion spaces that aren't just swamped with bots. We really need a reliable way of telling human from bot. I want to find a way to do that preserves privacy to the greatest degree possible.
Do you have any constructive criticism to offer? Maybe a suggested improvement, or an alternative way to accomplish the same goal? What's your solution to separate human from bot?
There is no need for it. Sorry. Certainly not government mandated, which is the worst part.
Frankly if you treat the internet like was did all the way back in bbs days, it doesn't matter that much: Everyone is a liar. So I don't care what anyone says. Bot or not.
In the forums I run we haven't seen much of a bot presence at all, so these spaces already exist. How do I know? We have all met each other at one point or another. So I may know a, a knows b, and so on.
Do I want the burden of starting authentication on top of this? No.
I don't want the internet to require me to get authentication. I really don't care about the bot issue. Go outside and meet people in real life if that's what you want.
There is no need for it. Sorry. Certainly not government mandated, which is the worst part.
YOU have no need of it. You're projecting your experiences onto everyone else. Maybe you're content only hanging out in limited forums where you have to know someone to join. And those forums can continue to operate without any human verification. If you don't care whether the spaces you occupy are infested with bots, or can manage with white lists, fine. But most people don't want to talk to bots. Not everyone has the social connections you do.
I don't support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn't mean no one does. Not everyone uses the internet the same way you do.
"Only join forums where you personally know the people there" is not a scalable solution to this problem.
Respect a diversity of viewpoints and experiences. Your way is not the only way.
You’re projecting your experiences onto everyone else.
In fairness, you are doing this right now.
I don’t support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn’t mean no one does. Not everyone uses the internet the same way you do.
You are free to create websites that function this way, or participate in websites that function this way, but don't push it on the rest of the internet.
“Only join forums where you personally know the people there” is not a scalable solution to this problem.
Sure it is. We didnt all know each other personally when we started, and people are welcome to join anytime. We just can figure out pretty quickly who is real and who is not because we meet each other. So what problem?
Not everyone uses the internet the same way you do.
Of course not, because they are either idiots, or never learned the basics. This is internet 101.
- Everyone is a liar.
- Everyone is anonymous
- Because of rule 2, see rule one.
You are commenting in a privacy forum. I quite likely am talking to a bot, or you are talking to a bot right? So don't listen to me, BUT: no matter how hard you try, making any system that requires any kind of verification on an internet wide scale WILL be abused.
Use the internet as intended and the problem goes away.
Edit: also, even if you filter the bots, the issues remain because in many ways people are just as bad. Misleading, argumentative, liars, agendas, half truths, etc. So it doesnt really matter.
But then how are you supposed to surveil citizens?
It would only work if the law mandated that this token cannot be stored or tracked across the web.
I think the idea is that you can use different tokens for each thing.
It's a legit idea, and there's a thing like that, called Zero Knowledge Proofs (ZKP).
IMO it's possible in theory. Like set up and managed in good faith, it can work mathematically, and you can prove it does.
My worry tho is that it wouldn't be in good faith. It'll be corrupted somehow. Or it turns out that enough other signals leak that it isn't very effective. Like fingerprinting and stylometry and w/e allow ID'ing despite the ZKP layer.
Maybe I missed something, but with your proposed solution, what would stop someone from just handing the adult cryptographic token to a kid? It sounds like it would be a similar situation to or even easier to do than fake ID cards or adults buying alcohol for underage people.
Nothing. Who says a solution has to be perfect? If "good enough" is good enough for handling the sale of alcohol, it can certainly be good enough for accessing web sites. No solution to any problem is perfect. You always have to find a balance between preventing the thing you want to stop and the negative effects of your efforts to prevent that thing.
It's not as good as the solution for alcohol as one bottle of beer making it to a child gets used up after only giving one child one drink. Once a token leaks, it can be shared again and again and used by arbitrarily many children arbitrarily many times until someone notices that it's leaked and revokes it (which then means that websites need to actively update a list of revoked tokens instead of just relying on public key cryptography to confirm it was signed by one of a few authorities, or all tokens will need to expire automatically after a short time).
That will always be the case for online age verification. There's nothing preventing an adult from signing up for an account and then just giving the account to a kid. This is true no matter the verification method chosen. Unless you're going to demand people scan their face every time they log in, and even then there are ways around it.
My goal is not to create a perfect solution. My goal is to create a good-enough solution that is as reliable as face or ID scanning, but without the privacy violations.
In that case, I suppose I agree with your solution.
How I see it, ocurres when the laws are made by ancients which confuse an remote control with an smartphone.

These kinds of laws will not succeed. People will choose to ignore them, like they ignore other laws, like they litter, jaywalk, drive 10 over the limit, run stop signs, etc. It will succeed in driving up prices on products from those companies who choose to comply, because they will be forced to hire in a lot more lawyers and compliance staff. These laws create lots of full time jobs in tech companies that few realize even exist. They have meetings every week, attend conferences, constantly send letters back and forth to each other. Then people wonder why their Gamepass fees went up $10 (its not actually the games)
so bye anything that isn't microsoft, apple or google? really tech independent of europe.
Can't wait for EU to ban general purpose computing. At some point ,everybody is just going to get a locked down Windows tablet where only EU approved software runs.
I fear that is the inevitable whimpered ending of the personal computing era. Cory Doctorow called it back in 2011.
Honestly, it's something where I wonder if we're doomed to end up there anyway.
I think that the AI companies vastly overstate the usefulness and danger represented by AI models. But the technology is only getting better, and the resources required to run models will decrease over time.
A common scenario brought up are AIs teaching people how to make biological weapons. Can existing LLMs actually do that? I really don't know. I for one don't feel like asking copilot, "please give me step-by-step instructions for obtaining and weaponizing anthrax, in steps simple enough someone with only a general science and engineering background can do." I'm curious what copilot would say. But I won't be asking copilot that, not because I'm incurious, but because I don't feel like getting my house raided by the FBI.
But imagine a world where that actually is possible. Forget the claims of Sam Altman. Let's look 50 years ahead in the future. Imagine being able to ask that question to an open-weight/model LLM, something you can run unmonitored on a home desktop, and actually getting a correct response. Imagine being able to ask endless follow-up questions. A good enough LLM could conceivably walk someone with only a high school education through all the steps needed to create weaponized anthrax from scratch.
Anthrax is something we actually can't control the spread of. It occurs naturally in the soil and water in some specific locations and conditions. A sufficiently skilled biochemist could go out, collect it, and culture it. And having an LLM capable of giving you step-by-step instructions, dumbed down to whatever your skill level is? Able to coach you through it, perhaps even watch you do it and offer real-time feedback? If you just have to act as the hands of the LLM? Suddenly anyone can weaponize anthrax.
I don't think existing LLMs are there yet. But what do we actually do if we reach a point where open-source LLMs are? What are we supposed to do when the knowledge to produce weapons of mass destruction becomes cheap and accessible?
A general trend in technology over time is that it has magnified the potential destructive power of a single individual. How can a society survive when anybody has the ability to kill everybody? I just don't see how you keep society going except by locking down the tech. Maybe require a license for any computer over a certain power. And such computers are heavily surveilled. So you can have a free and private computer, but only if that computer does not make you a danger to everyone around you.
I just don't know how else a civilization can survive the democratization of weapons of mass destruction.
Indeed
Can't wait to become a shady dealer who sells pre 2026 computers with highly illegal software running on it (such as debian)
There's gonna be a whole black market for smuggling open computing platforms from China 🤣
The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.
The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.
So there's a chance that GrapheneOS will be supported. I mean, we can still decompile the app, modify it and then repackage it. Or someone will make a patcher app.
I would love to be wrong about this, but I don't think it's likely. Why would a government voluntarily spend money on making the app work for a minority of people running a privacy OS that politicians associate with criminals and gangsters?
Also, it's not like the wallet app will actually be open source in the traditional sense where you can fork and compile it yourself, so I think getting any decent version of it seems like a long shot
Graphene will likely ignore the EU, as will most Linux distros having no EU connections. Graphene's very picky about hardware, which is why they stick with the Pixel, but anyone with the cash can pay an OEM to make a phone to their specs and install whatever Android or Linux mobile variant they want, then make 1000 or 10,000 of them to sell.
The whole thing is wrongheaded in the first place; any child wanting to access adult-only content will use an adult’s account to do so; any adult attempting to access adult-only content is likewise going to use an adult’s account.
So unless they’re tying this to biometrics that are actually secure against an adverserial child, all the system really does is creates a registry of adults. And we already have those.
I think they expect the parent to secure their own account to make sure their child can't use it. And anyways, it shifts accountability. If the parent lets the child use their account, then the parent takes the blame. If the child gets addicted to social media, that becomes the parent's fault for giving the child unrestricted access.
Creating a registry of adults and what content they access is exactly the point of these laws. Always has been. "Protecting children" is just the easiest excuse to make it seem more urgent to violate people's rights. Just like removing trans healthcare started with children and is now targeting adults.
Wasn't there something about the effectiveness of the Australian law to restrict minors on social media? Ah...
Four in five under-16s in Australia using social media despite ban, study shows
Experts say law not enough to stop children accessing harmful content online and more ‘convincing strategy is required’ . More than 80% of under-16s in Australia said they were still using social media three months after legislation banning them from it came into force, research shows.