| ▲ | Xelbair 10 hours ago | ||||||||||||||||||||||||||||||||||||||||
In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper. How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from. It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points. Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished. Legal systems aren't computer systems. This isn't a technical problem but a social/political one. | |||||||||||||||||||||||||||||||||||||||||
| ▲ | ben_w 9 hours ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||
> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from. True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference? > It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points. This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID. > Legal systems aren't computer systems. This isn't a technical problem but a social/political one. While true, the reverse also applies: computer systems are not legal systems. I think many lawmakers' ignorance of this is to the detriment of everyone. In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material. The options-space for doing this appears to be: (0) give up (1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?") (2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR") (3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed. But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc. It doesn't need to be perfect, the kids aren't a computer program. What does need to be held to a high standard is making sure the OSes don't leak all over the place. * to be specific, the Investigatory Powers Act 2016 is one of two reasons I left the UK, just look at how over-broad the "Internet connection records without a warrant" list is https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#... | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||