Comment by data-ottawa

1 day ago

I'm writing my (Canadian) MP to this effect.

There are a lot of issues with the UK approach. Privacy is a big one. But requiring this on every service is both a tax on the service and requires constantly authorizing stuff. That opens up the possibility for scams, data misuse, etc.

And no, saying we said to only use the data for verification clearly doesn't work. It didn't work for discord, or Persona, or Tea or AU10TIX or any others. Verification now means sharing that data with credit agencies and third party databases. Verification means keeping some data to resolve customer support disputes. There's data leakage for training and creating derived data products like biometric embeddings for future use.

Third party verification is a security nightmare.

I don't know why device based approvals abd controls aren't considered at all. Or really any privacy preserving technique.

And all this for ~54% efficacy?

There is no such thing as privacy protecting or anonymous age verification. If you tell Canadian that such a thing is possible, they are guaranteed to harm privacy with any legislation they proposal. Just tell them no.

  • > There is no such thing as privacy protecting or anonymous age verification

    There most definitely is privacy-protecting age verification. You go to a government office, you show your ID, they give you a piece of paper that officially says "over 18 years old". Now you have a piece of paper that says you're over 18 but doesn't say who you are, and the government won't know where you use it.

    On the Internet, the idea is the same, but with cryptography.