today I created a burner google account. these days google requires an Android phone in order to even create an account so I used an old phone to scan the QR code ( I am pretty sure this lets google grab all of the metadata of the mobile phone ). after about 1 hour creating the account. google's automated system disabled the account however I appealed and got the account back. before someone asks I need google because of where I live.

this made me wonder what if google mandates age verification? if there were age verification google would immediately notice that I am creating another account ( burner account ) which it won't like. burner account won't be created in the first place!

we already have too much surveillance and this makes it worse. my mobile number is already tied to my read government identity. I DO NOT want my online account to be tied to my read identify too! it is sad, it really is

top 50 comments

sorted by: hot top controversial new old
[–] 21 points 4 weeks ago
[–] 15 points 4 weeks ago (27 children)

The EU is building the EUDI wallet (or rather requiring each member state to provide a solution) and it will be possible to prove your age with that without disclosing details about your identity. And it's even possible to do this on your device, so the state won't know who you're proving your age to. Just saying that there are ways to do it right. It's just a matter of whether everybody wants that.

  • source
  • hideshow 27 child comments
  • [–] 15 points 4 weeks ago (3 children)

    Nope, it won't be anonymous.

    Look, any kind of digital age verification must be connected in some way to an actual identity.

    If you are running a community operating under EU laws to require age verification, then a simple true/false statement won't cut it.

    You will be required to log a personal ID number of the user, signed by the digital wallet issuer, that is the only way to guarantee that a specific person was verified to be of age.

    You as an admin of the community might not know the identity of the users, but the government can tie the account back to you.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 0 points 4 weeks ago (2 children)

    The EUDI wallet is advertising that it can prove your ID on device and just send a "is over 18" confirmation. So at least in theory, the wallet should provide verification without giving your ID to whatever service you want to use. I do doubt however, that ot will work that smoothly and securely in practice

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 3 weeks ago*

    The EUDI wallet is advertising

    ADVERTISING. Don't treat marketing as truth

    So at least in theory

    No, there's no theory here. Just lies.

    As Louis Rossmann once said: Dont accept the premise of assholes. Don't repeat their lies for them.

  • source
  • parent
  • [–] 14 points 3 weeks ago* (13 children)

    Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets

    The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user's access to a service, essentially removing that person’s access to the internet entirely.

    a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.

    Personally I'm optimistic that tech like this can be used in positive ways, but imo they should be developed transparently (open source) and decentralized.

  • source
  • parent
  • hideshow 13 child comments
  • [–] 2 points 3 weeks ago (9 children)

    How could the issuer track when a credential is used? Isn't the whole point that the issuer isn't needed for verification of the ZKP?

  • source
  • parent
  • hideshow 9 child comments
  • [–] 2 points 3 weeks ago (8 children)

    Because the credential is unique. Imagine you submit it every time you log into Google, Facebook, and Youtube. They could all collude and see that the same age verification token was used and link the accounts.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 3 points 3 weeks ago (7 children)

    They are use once tokens, you get given like 50 or 100 when issued. There's no way to link them

  • source
  • parent
  • hideshow 7 child comments
  • [–] 1 point 3 weeks ago* (last edited 3 weeks ago) (6 children)

    If they are use once tokens then you need to get more. If implemented badly, they could be asking for a new one every time, and now the issuer knows whenever you are using them. I'm not sure exactly what implementstion flaws The EFF article was talking about but they have links if you want to learn more.

    Edit: also, now that I think of it, if it's single use, then they need to be invalidated every time they are used. So this probably also notifies the issuer every time a token is used, and which token it was. There are probably ways to do this privately but it is a tricky problem, and something the government probably won't get right the first time, which is the main issue that the EFF is talking about.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 1 point 3 weeks ago* (5 children)

    The single use part is just for your privacy, they don't have to be invalidated. You could just have them last a week or <time interval> on issue

  • source
  • parent
  • hideshow 5 child comments
  • [–] 1 point 3 weeks ago (4 children)

    You're talking about potential implementations. EFF is talking about issues in current implementation. As I said in my very first comment, I'm sure it can be done properly. The EFF is worried that if the current implementation is rolled out now, the system will stay unfixed for years and make privacy even worse.

    But anyways, since you seem knowledgeable about the EUDI implementation and I'm too lazy to look it up, do you know if the current implementation allows a website to collude with the issuer to get the identity of a user?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 3 weeks ago (3 children)

    My reference point is cloudflare's research on zero knowledge proofs used to issue anonymous tokens to bypass (pre-complete) captcha checkpoints.

    Neither website nor issuer (nor the combination) can determine the identity of a user from the token (hence zero knowledge), but other techniques entirely unrelated to the cryptography can identify a user. For example network or browser metadata or traditional browser fingerprinting.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 1 point 3 weeks ago (2 children)

    I see so it seems like we were talking past each other. I'm aware of Cloudflare's token system. As well as other systems like GNU Taler and Monero. So clearly privacy preserving systems can be built. But I also trust the EFF, and if they say the current system has major flaws I'm inclined to believe them

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 weeks ago (1 child)

    The age verification system can't be zero knowledge if they know what your token is, and can track it. Seems a bit funky

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (3 replies)
  • [–] 6 points 4 weeks ago*

    Storing identification information on an internet-connected system will never be safe for the people whose information is collected there. Such databases are high-value targets. They always get attacked, and the information stolen. This cannot be done safely.

  • source
  • parent
  • [–] 7 points 4 weeks ago (3 children)

    I am pretty sure this lets google grab all of the metadata of the mobile phone

    Android is a Google product. They have full control over it. They can "grab all the metadata of the mobile phone" (whatever that means) any time they like.

  • source
  • hideshow 3 child comments
  • [–] [S] 2 points 4 weeks ago (2 children)

    yes, but in this case that metadata is now attached to the newly created burner account. and if you use your personal android device then google knows that it's your burner account.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 4 weeks ago* (last edited 4 weeks ago)

    Do you know what de-anonymization online can do?

    Exactly, de-anonymize you, based on your behaviour patterns collected over years and decades and any data they can lay their hands on. It doesn't matter if you switch accounts or phones or both every week or even type of device.

    If every one of your new accounts/devices is at the same place, is awake at the same time, uses the same apps, has the same typing rhythm, browses the same websites at the same time of day and logs in with the same accounts and sings the pokemon theme song in the shower every morning and walks in the park twice a day with dog barking and "good boi" sounds happening in closest proximity to the tracking device you carry in your pocket - they'll be pretty sure it's the same person.

    Wasn't there a scandal just last week about Samsung smart tv's recoding audio nonstop and sending it to their servers, even when they are "turned off"?

    And even if you are a hermit that cut off all their devices and access to the internet altogether, other peoples devices will collect data about you, enumerate you as a seperate entity from the device holder and keep collecting and patternmatching.

  • source
  • parent
  • [–] 6 points 3 weeks ago

    For many people, yes, I think it will lead to the end of anonymous accounts, but for many others, it will lead to innovation in bypassing age verification.

  • source
  • [–] 5 points 3 weeks ago

    Wait, I have to set up burner accounts all the time for Red Team engagements and you can usually get a google account with SMS verification only. Are you sure you're doing it correctly? are you doing it from Tor or a VPN or an internet café?

    Why would your country matter in the process for an internet account if you can use an IP from virtually anywhere?

    All these tiny details matter for your OpSec, and every choice also affects how hard you trigger abuse prevention mechanisms from service providers.

    Details aside, yes it is getting harder and its insane that you need actual professional skills to maintain privacy, where it should be the default.

    Educate yourself and your loved ones on surveillance self-defense: https://ssd.eff.org/

    Also, lmao at expecting privacy from anything Google.

  • source
  • [–] 4 points 4 weeks ago (4 children)

    Why use Google or any of the big US tech firms for burner accounts then?

  • source
  • hideshow 4 child comments
  • [–] [S] 3 points 4 weeks ago (3 children)

    because of where I live. people find it suspicious not having google account.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 4 points 4 weeks ago (2 children)

    Now that’s suspicious as hell

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 1 point 3 weeks ago (1 child)

    wdym? can you elaborate please?

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 weeks ago

    A person does not own a Google account. A Google account owns a person. This is the reason behind identity verification. They use that information to track and profile a person both online and in the real world. If it's more suspect to use privacy focused providers then I'd be concerned how that became normal. Google is both using that data and feeding it to whoever will pay for it (for example, your government). I've attended private Google product demos that have focused on these capabilities.

  • source
  • parent
  • [–] 3 points 3 weeks ago*

    google started limited the accounts created, allegedly to combat botting/spamming, and from AI SCRAPing. they have a deal for Reddits data to AI scrape, i think google is helping them out trying to force genuine users content, it pretty much conincides with reddits forced login. because botters and spammers create hundreds of google accounts to verify with reddit(as trustworthy to keep it from getting shadowbanned)

  • source
  • [–] 3 points 3 weeks ago (1 child)

    Google already has the imei of that old phone associated with you. Once you start using that phone online and they are tracking to, they'll be able to confirm it's you.

  • source
  • hideshow 1 child comment
  • [–] 2 points 3 weeks ago

    I set up burner accounts on proton.me. But anyway, you are right. Sadly enough, you only needed a reliable, standardized system that gives back if you are below or on and beyond a certain age threshold, but BigTech and their bootlickers already started to implement age verification with proprietary apps, exploiting every ID detail they get, and legally required BigTech accounts, services, and stores.

  • source
  • load more comments
    view more: next ›