Remix.run Logo
WhyNotHugo a day ago

> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.

If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.

Elfener a day ago | parent | next [-]

And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.

(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)

zenoprax a day ago | parent | prev | next [-]

> The project’s position is that hardware binding remains required

I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?

I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.

Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.

filleokus a day ago | parent | prev | next [-]

If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.

The key material must be DRM'ed, especially if some ZKP solution is used.

Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.

(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)

10polkoranin a day ago | parent | next [-]

Perhaps one could construct a bond-based system. It wouldn't help family collusion, but it would help limit people of age selling their authentication ability.

Say you have a public service and a platform site (social media, gambling, whatever), and the user does authentication in a way that anonymously proves to the platform that they're of age while revealing nothing else, and without revealing to the public service what platform they're accessing. But the protocol requires some expensive data (token that provides access to a bond account) which anybody MITMing the protocol can obtain.

Then if Alice tries to sell her age verification abilities to Bob, the protocol could be designed so either Alice learns the negotiated key and can snoop on everything Bob does, or she has to let Bob do a man-in-the-middle over a channel and lose the ability to observe what's going on after the first key exchange; and then Bob can acquire the token and make use of it at a later time.

This is very handwave-ish, but I don't think such a protocol would be impossible to design.

Under normal use, Alice has no reason to drain her own bond account. But if she's selling to an anonymous crowd who might use the token at any time (hence she can't trace the traitor), some troll is eventually going to do it.

matheusmoreira a day ago | parent | prev | next [-]

> If you want to actually enforce age restrictions

I don't.

This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.

dwattttt a day ago | parent [-]

Do you also oppose drivers licensing, alcohol age limits? Those rely on a trusted ID managed by a government.

matheusmoreira a day ago | parent | next [-]

Not exactly a fan of those either, but they're much easier to tolerate because so far they aren't implementing a surveillance state straight out of a cyberpunk dystopia just to prevent kids from driving or drinking.

It's not like the car refuses to start if a dad tries to teach his kid how to drive.

imtringued 20 hours ago | parent | prev [-]

I have never been asked to show my ID ever in my entire life when buying alcohol.

The alcohol age limit equivalent would be to put the entire TPM + proprietary software infrastructure into the cash register, locking in a monopoly on what software can be used on cash registers. Not to mention, you now have to scan your ID, which then obviously gets recorded forever, allowing the government to track your alcohol consumption.

Yeah, I'm against that and I don't even drink alcohol, not even the alcohol I've bought myself as a gift to my parents.

zarzavat a day ago | parent | prev | next [-]

Xkcd 538. Hardware attestation is not required because it's not sufficient, you need to plug all the other much easier ways to get around the system.

Firstly, you need to comprehensively ban VPNs, probably with some great firewall setup.

Secondly, you need to install CCTV in people's homes to make sure that nobody uses someone else's device to get around the system.

Then it's time for hardware attestation.

zb3 a day ago | parent | prev [-]

> I don't see how we can avoid the "trusted" hardware requirement.

While this is a good point, what's missing here is that this hardware doesn't have to have Google spyware and other bloatware installed. Yet with current design, this becomes mandatory.. security requirements are abused here to force unrelated software on my computer that I have to carry with me in order to participate in society.

This app should work on a dedicated device, something like a smartcard with e-ink display.. it would even be more secure because it would have less attack surface. Just like today I'm not complaining about not being able to install linux on my credit/SIM card, I'd not complain about that either. But locking down the whole OS on my smartphone is unacceptable.

afandian a day ago | parent | prev | next [-]

We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.

We did it before. We forgot at the time when things were more-or-less free.

(I don't know how we do this. I'm as dependent as ever.)

big85 a day ago | parent | prev [-]

So much for the EU's mission to reduce e-waste.