You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
installing an age verification app on a mobile device
on all other devices - you scan QR code with the age verification app.
I find it generally problematic.
There are so many desktop PC and laptops around with TPM aboard, with basically ready infrastructure to store private keys and usable to sign data such as age attestations.
There are usb-attached keys storages and signers which can be used to store necessary private keys too.
Even a dedicated device can be developed with monochrome screen to show QR codes, USB, NFC and Bluetooth interfaces with support of FIDO2 standards like Webauthn, and with only dedicated age verification or full EUID with age verification software preinstalled, without any involvement of e. g. Google or Apple. Benefit of such dedicated device can be many, including:
lack of dependency on Google & Apple
energy efficiency coming from engineering simplicity and lack of audio, camera or energy-expensive colorful display.
reduced attack surface because of lack of various attack surfaces, literally due lack of GPS, Wifi and internet access to function or absence of "random apps installation" on that device what often seen in cybersecurity as an attack vector as well.
As I see the most strong debates are about what to do with mentioning only Google Play Services and Apple its equivalent, and lack support of other mobile OSes, but I see the problem much wider - the whole idea defined in too narrow way, like authors spec are mobile apps developers with experience in stock Android and iOS, while the problem they trying to solve can be solved in many different ways, and there are many people who prefer to not have a mobile phone at all and prefer instead have laptop or desktop PC and dumb phone, and for this audience it would be easier to use flow with SMS-based OTP for age verifications.
I have an OTP device from my bank. it has a tiny 6 digits display and a button. When I press the button, it shows the 6 digit OTP code. This device works for years without replacement. Why something like that can not be used for age verification as well?
I listed many ways of how age verification can be done not only to show that it does not necessary to be about having a smartphone with software controlled by Google or Apple, but also to remind that making the whole spec so narrow will cause digital segregation and exclusion.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
I seen the the spec mentioning only 2 scenarios:
I find it generally problematic.
There are so many desktop PC and laptops around with TPM aboard, with basically ready infrastructure to store private keys and usable to sign data such as age attestations.
There are usb-attached keys storages and signers which can be used to store necessary private keys too.
Even a dedicated device can be developed with monochrome screen to show QR codes, USB, NFC and Bluetooth interfaces with support of FIDO2 standards like Webauthn, and with only dedicated age verification or full EUID with age verification software preinstalled, without any involvement of e. g. Google or Apple. Benefit of such dedicated device can be many, including:
As I see the most strong debates are about what to do with mentioning only Google Play Services and Apple its equivalent, and lack support of other mobile OSes, but I see the problem much wider - the whole idea defined in too narrow way, like authors spec are mobile apps developers with experience in stock Android and iOS, while the problem they trying to solve can be solved in many different ways, and there are many people who prefer to not have a mobile phone at all and prefer instead have laptop or desktop PC and dumb phone, and for this audience it would be easier to use flow with SMS-based OTP for age verifications.
I have an OTP device from my bank. it has a tiny 6 digits display and a button. When I press the button, it shows the 6 digit OTP code. This device works for years without replacement. Why something like that can not be used for age verification as well?
I listed many ways of how age verification can be done not only to show that it does not necessary to be about having a smartphone with software controlled by Google or Apple, but also to remind that making the whole spec so narrow will cause digital segregation and exclusion.
All reactions