• 0 Posts
  • 68 Comments
Joined 4 months ago
cake
Cake day: January 20th, 2026

help-circle

  • That “ready” is just typical political advertising speech. Could have been worded more carefully, but it’s forgivable. As long as the git repo and website correctly identify it as a demo/prototype, it seems fine to me. E.g. not using the security enclave is totally fine for a demo. It doesn’t affect the general protocol design. There’s a lot of hostility both to these initiatives as well as to the EU (often by different actors, there’s e.g other countries pushing for less privacy respecting mechanisms), so the clever criticism tends towards nitpicking. There’s actually merit in releasing such an ambitious project as open source and so early, which even with the nitpicking and negativity, is a good thing.





  • linule@lemmy.worldtoEurope@feddit.orgThe EU says its age verification app is ready
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    1 month ago

    And how does that process guarantee that your token identifies only you? It seems that an adult can go to the store at different times and get n tokens, which they can then give to minors.

    To your edits, indeed, the server handling is what I was alluding at previously with possible issues, specifically in the verification part. But that’s the good part that there’s an open source project, where these questions can be raised. It seems more complicated, but maybe not impossible to guarantee privacy on a trustless way also there.

    As to the use, I imagine that it can be extended to other things such as proving that you’re a human, which is becoming pretty much impossible. It might be the most effective solution for “dead internet”.


  • linule@lemmy.worldtoEurope@feddit.orgThe EU says its age verification app is ready
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    1 month ago

    The government derives the token from the id, which it created and knows, so there’s no privacy loss there.

    Nothing is distributed to third parties, the third party just verifies the token with the government service and gets ok / not ok. It never sees any id data.

    In your example, how do you know that the third party is not storing the data when scanning it? And how do you deal with online services?

    The issues described in the article are serious, but not fundamental design flaws of the protocol, and it depends on how they’ve presented the app: did they say it can be used already? if it’s just a prototype it’s ok to e.g not store the token/pin in the security enclave yet. And the issues being easily found is facilitated by the project being released as open source, which is good. Not saying that everything is perfect, and there might be actual issues with the protocol, but this isn’t it. It’s in any case better than having to share your id with N third parties.












  • What you’re describing is absolutely not my thinking, I very much agree and in fact bring up myself often that collective action should be the norm. I just see politicians as part of this collective, and within the context of representative democracy where we currently live in, expected to be more aware of political context and meaningful action, because that’s literally their profession. Collective action should exist regardless and if needed “help” with the shortcomings of incompetent representatives, but in any case it invites to look closely at how well representatives are qualified, and motivated to do their jobs.