Do you need to verify your age to perform a Google search?
I think "age verification" is just another "think of the children" ploy to force all websites to check their users' government IDs (starting with sites run by people whose politics are different from those of the government that's enacting the ploy).
> children can not enter a library and get Adult books
Is that true? Can a 13 year old child in Italy not walk into their local town library and pick a novel off the shelf and start reading all sorts of violent and explicit narratives? Not to mention all the medical textbooks, and books containing images of artistic works depicting undressed humans.
I'm glad you agree that knowing someone's name, age, and address doesn't prove their trustworthiness, because I don't want trust decisions to be dependent on threats of state-backed violence or mob vigilantism.
It is possible to build up trust in an identity based on how long that identity has been used, and the "transitivity of trust" principle. So you wouldn't trust someone because "John sounds like a trustworthy name", and instead you'd look at how long the author's key had been associated with the library, and whether their key had previously been endorsed on other people's projects (for example having their PRs reviewed and accepted).
Admittedly this introduces a new danger that the social graphs start to become very dangerous honeypots of metadata, especially if we start letting employers vouch for their employees, but the ultimate goal here should be to use something like Verifiable Credentials with zero knowledge proofs, which will allow very strong probabilistic arguments to be made about whether an author (and all the code reviewers) have suddenly gone rogue and decided to burn their hard-earned reputations.
The first step in solving the trust problem is solving the identity problem. At the very least, once you've got cryptographic identities for entities involved in your supply chain, you can use a TOFU policy and check whenever an identity changes.
Simple operations like rotating a key shouldn't trigger any security warnings, as long as they new key is signed by the old one, and even adding new people to a team should happen seamlessly if (a majority of) the existing team members approve that new identity being added.
Of course it doesn't solve key compromise, or someone selling their keys to someone else, but with long-lived (even pseudonymous) identities, it becomes possible to reason about the trust level of packages just based on how long an identity has been used without being compromised.
No system is perfect, and there's still a long way to go, but the existing systems make the remaining problems more tractable, and already increase the cost for attackers, which should reduce attacks.
Isn't this just like the situation in 2014 where academics were arguing that 'gain-of-function' experiments were dangerous[0], but big government labs and pharma companies were too excited about the research and treatments they could produce?
> Sure and they'll be quickly mistrusted. You can't really revoke DNNSEC trust of an ccTLD operator.
But you don't have to, because the blast radius is so much smaller, and the incentives are aligned better. The reason why CAs require such extreme punishment for misbehaviour is that one bad CA can break the trust for every site on the web.
If a country decided to invalidate the security of (predominantly) its own citizens' websites then that wouldn't harm anyone who used any of the other ccTLDs in the world (not to mention the hundreds of gTLDs).
Also, I think you are over-estimating the ease with which a CA can be "quickly mistrusted". What is the record for how quickly a CA has been taken out of browsers' certificate stores, measured from the time of their first misissuance?
And I would argue that revoking CA trust to Let's Encrypt / IdenTrust would be much more disruptive than revoking a single ccTLD operator, since that would mean breaking most sites on the web. So DNSSEC is actually better in terms of the "too big to fail" problem.
> This is bypassing a dangerous design, at best.
But that's my point; DNSSEC lets you bypass the danger of a rogue issuer, by swapping to an alternate domain in the worst case, whereas with CAs you have to hope that the rogue issuer doesn't decide to target you, and wait for the bureaucratic and software update processes to remove that CA from all your users' browsers.
There are definitely limitations to the DNSSEC system as currently deployed, just as there were with the web PKI system before browsers started to patch all the holes in that, but I don't know why my position on this technical question is so controversial. Nevertheless, I really appreciate you taking the time to offer intelligent counter-arguments in your comment, thank you.
> DNSSEC, ... still does not work in most TLD and registers.
I'd be interested to know where you get your data from. By my count, there are 142 ccTLDs that support it and 106 that don't, out of 248 ccTLDs.[0]
That's already more than half, but if you include the gTLDs then the number of TLDs signed in the DNS root goes up to 92% according to the best data I can find.[1]
Trusting the country that operates the ccTLD of your website is a much better situation than having to trust all the countries that have CAs operate in them.
A malicious CA in one country can issue a fraudulent certificate for a site in another country, whereas the people operating .ru can't affect the records for example.us so the blast radius is limited by design.
Moreover, no one is required to use a ccTLD, and there are hundreds of gTLDs to choose from, or you could even run one yourself if necessary.
Do you think that the state shouldn't be allowed to kill unwanted Down syndrome babies after they are born because "that's eugenics"?
What about Down syndrome adults, who are reliant on state benefits?
In case it's not clear, I don't support the killing of disabled people at any age, but I understand that different people approach these questions from a different set of assumptions.
My point is that adding scare quotes around "that's eugenics" doesn't stop it from being an accurate description, so your question is not the gotcha you might think it is.
> If something else with the right properties comes along then we'll adopt it
Have you looked at DID-SIOP?[0] It's based on the "Self-Issued OpenID Provider" extension[1] to OpenID Connect, to make it easier for existing OIDC relying parties to support those identities.
"Controlling the output of generative AI technology is simple. We will create context for its use. First we will censor any use related to social taboos. Then we will censor anything else that we desire. If anyone complains, we will accuse them of wanting to engage in or promote social taboos."
No, but they might ban "bespoke" devices.[0] Maybe you're smart and brave enough to build and maintain your own illegal device, but good luck trying to persuade other people to do the same so that you can communicate with them securely online. Also, the government might force ISPs to block access to devices that don't pass remote attestation checks.
Except the EU is pushing for chat client interoperability[0], and side-loading[1], so everyone should be able to switch to open source apps that don't have this Kafkaesque "your guilt is decided by the AI" feature.
The reason why DRM has failed in the past is that it only takes one person to crack the DRM on their own device, and then they have an unencumbered digital file which can be copied and distributed freely.
Applying DRM to kernels and applications rather than to media files is completely different. If someone wants to have an E2E encrypted conversation, not only do they have to have jailbroken their own device by extracting the secret keys from inside its processor (using an electron microscope, perhaps) but their conversation partner has to have done the same to their own device.
Even if a few brave and well-resourced journalists/lawyers/activists managed to do this among themselves, they would quickly be exposed by traffic analysis, allowing the government to simultaneously arrest all of them and use their devices as evidence.
> Even with attestation you could just daisy chain and use the attesting device as a proxy.
But you'd need the attested device to run the proxy server software, which would obviously not be allowed in the app store, and would be blocked by the gatekeeper daemon or the OS-level firewall. Well, proxy software would be allowed, but it would have to perform its own attestation checks on the devices it proxies for.
> Not to mentioned the billion of internet enabled devices that would never support it
The billion internet enabled devices would be allowed onto a special "safe" segment of the internet, which companies could apply to add their static IPs to. So your internet connected fridge could still phone home, but the manufacturer would take liability for any data that a rooted fridge managed to send out to the internet.
There might still be millions of old devices that don't support TPMs and don't have manufacturers willing to apply to have their IPs whitelisted, but the government will say that kicking these insecure unpatched devices off their internet would be a huge win for cybersecurity. Making people buy a whole load of new devices would probably also give a temporary boost to the economy too.
> The absolute size of the risk is what's relevant.
But you weren't talking about the absolute size, you said "a very small problem compared to things like" (my emphasis). Please at least admit you were wrong about that.
In any case, as an absolute number, even one school shooting is too many, and if the US government can devote resources and legislation to reducing traffic accidents and drug overdoses harming children, then there's no reason why it can't do the same to reduce gun deaths, like every other civilized country does.
> Like everywhere in the United states, it's young Black men killing other young Black men
You may be surprised to learn[0] that "Black men and boys ages 15 to 34 ... were among 37% of gun homicides" in 2019, so most killings are not like what you describe at all.
Do you need to verify your age to perform a Google search?
I think "age verification" is just another "think of the children" ploy to force all websites to check their users' government IDs (starting with sites run by people whose politics are different from those of the government that's enacting the ploy).