I am not a velociraptor

  • 0 Posts
  • 16 Comments
Joined 8 months ago
cake
Cake day: November 26th, 2024

help-circle









  • the only way to borrow it is physically taking the phone, and even then, if the phone is locked, you need to unlock it. The cert by itself is bound to a device, if you give that device to someone else, that’s on you. It’s not a fault in the system but in the user.

    Think of how 2fa apps work. They generally are locked under a code or biometrics, if someone else access to them, it’s because you gave them access, so it’s your responsibility.


  • Yeah, my idea comes from them. We are trying to find a “new” solution to a problem when there has been one ready for years and we only need to adapt it to this system.

    As long as the key to create new certs is kept safe (and given that the auth is the govern itself, I’d say they will be kept safe), you don’t need to worry about false certs. And even if the key got stolen somehow, all you need to do is change it and deprecate the old one so new certs using the old key won’t be valid.


  • AbsolutelyNotAVelociraptor@sh.itjust.workstoscience@lemmy.worldAge verification
    link
    fedilink
    English
    arrow-up
    36
    arrow-down
    2
    ·
    edit-2
    2 days ago

    The solution is really, stunningly simple:

    Your gov issues official documents about you (driving license, passport, id cards…). They know your age.

    Your gov is also a trustworthy institution since all those cited above are official documents that anyone, anywhere will accept as valid.

    So here’s the solution: the gov creates a digital certificate in which the only stored data is your age, or even less: your adult state (as a boolean; if over 18 = TRUE).

    The gov issues the cert on demand to any person after presenting any valid ID to prove who you are (it can be done online, with only the id verification being done in person). The cert is bound to your device, and if you change phone, you must migrate it so you can’t have it in two devices.

    Since the issuer is a trusted authority, the cert can be used as a proof of age in any site needing it as the only thing they need is to read the cert and confirm the auth of the issuer.

    And as the cert is only a boolean status saying if you are underage or adult, there is no privacy concerns as the one checking your age won’t know anything else about you.

    There, you just solved a “huge” problem in a simple way and with no privacy concerns.


  • I think some people use downvotes as a disagree button. They don’t like the idea of paying a sub for a launcher (I too find it stupid but that’s just my opinion) and use the downvote to let the world know instead of commenting or simply ignoring the post.

    Don’t take it personally, and please don’t let the downvotes discourage you! Your posts are a breeze of fresh air content in a place where most content is just links to news sites.



  • The trick is using something you can easily remember but also not obvious. For example: take your favorite book, pick the first sentence of the first chapter and change vowels with numbers. There, super easy to remember password, but almost impossible to guess.

    Instead, you can use anything: the second sentence of the book, the name of your favourite song (or songs if the song is just one word), the lyrics of that song…

    Just something that is easily accessible in case you forget but nobody could ever guess


  • Generating a password (or, actually, anything in general that involved some imagination and abstract creation) was the bane of my existence.

    So when I managed to find an ingenious password that was both easy to remember and not obvious without the right hint, I was thrilled. I used it for 10 years straight.

    Fortunately, the internet then was not the dangerous place it is now so you could safely reuse passwords everywhere.

    Then I discovered password managers and they changed my life. There’s only one password I need to remember now.