• 6 Posts
  • 417 Comments
Joined 2 years ago
cake
Cake day: April 27th, 2024

help-circle


  • So for context, I actually drink, more than I probably should. I have a well stocked home bar, and trying or inventing new cocktails is almost a hobby for me and my partner.

    I also come from a country with a veeeeeeery ingrained alcohol culture.

    I’d still vote for an alcohol ban. Yes this is hypocritical when looking at my current habits. I don’t really have a point here, beyond saying that, even if banning alcohol is unrealistic, drinking alcohol being gone from the world is still a good idea in principle, the same as with tobacco.




  • I think the text is somewhat dubious in its arguments, but this (and the arguments built on this assertion) is just plain wrong:

    [Signals servers have] a few important pieces of data;

    Message dates and times Message senders and recipients (via phone number identifiers)

    Signal clients implement the Pond protocol. As a result, Signals servers know who a message is for (obviously, how else do you get the message) but cannot know who it is FROM.

    I’ve been playing around with implementing a secure/private messenger demo for myself, and have been consistently impressed with how privacy preserving Signal is when reading their papers and code. I wish it was selfhostable, but apart from that, it’s great.

    The server would be NICE to be OSS, but ultimately, privacy breaches are prevented client/protocol side.




  • This doesn’t make a call to government servers.

    The app (or desktop application BTW, incl. Linux) reads your national ID’s NFC tag, once. When you need to prove your age, the app locally computes a zkp that only tells the site “at least 18yo yes/no”.

    Note that every EU country has a form of national ID, and the digital capabilities of these IDs are already used for a bunch of stuff (e.g. taxes, bank account creation,…). This doesn’t worsen the privacy situation for EU citizens, but instead ensures that no privacy-unfriendly solutions emerge.










  • It’s mostly just that I don’t want the government to know precisely which websites I visit. Nor do I want the the porn sites to know exactly who I am.

    I understand, I want that too. It’s easily possible though (just one example for a scheme):

    • you visit porn site
    • porn site sends your browser a random nonce
    • you/browser tell government service: sign this if I’m >18
    • government signs the nonce + a timstamp to prove freshness
    • your browser forwards the result to the porn site
    • porn site can verify signature per standard public certificate chains
    • now porn site has proof that you are >18, but knows nothing else about you; and government only knows that you wanted proof that you are an adult, but not for what site or purpose you wanted to prove that

    Alternatively, if we go the “device has an age bracket field browsers access” route, it’s even simpler, and just as if not more privacy preserving.