• Darkard@lemmy.world
    link
    fedilink
    English
    arrow-up
    510
    ·
    7 days ago

    But don’t forget guys, uploading your government IDs to any old fucking website to prove your age is very safe and protects children. There’s no way this could go wrong and everyone in the supply chain is very trustworthy

    • Saapas@piefed.zip
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      102
      ·
      7 days ago

      The QR/one time code way makes a lot more sense and avoids this issue

      • BooBees@fedinsfw.app
        link
        fedilink
        English
        arrow-up
        161
        arrow-down
        2
        ·
        7 days ago

        How about we just don’t suck the dicks of authoritarian wannabe dipshits that have proven they can’t secure any information properly and can’t run any institution properly?

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          51
          ·
          7 days ago

          I don’t know exactly what you mean, I just think for age gating there’s ways that are a lot better

          • Sturgist@piefed.ca
            link
            fedilink
            English
            arrow-up
            83
            arrow-down
            2
            ·
            7 days ago

            Like parents actually parenting and activating the built in restrictions for their children’s devices?

            • AustralianSimon@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              6 days ago

              The whole credit card system worked until pron websites gave you stuff for free. The average kid couldn’t acquire a credit card without being caught.

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              56
              ·
              7 days ago

              It’s probably more effective done at the other end. It’s not like you can make parents parent

              • BooBees@fedinsfw.app
                link
                fedilink
                English
                arrow-up
                32
                arrow-down
                2
                ·
                6 days ago

                You actually can, it’s called regulations, policies and enforcement. Don’t vaccinate your crotch fruit? Cool, they can’t go to public school, and you just won a visit from child welfare

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  21
                  ·
                  6 days ago

                  It’s not like we don’t have regulations, policies and (some) enforcement. But there’s still dogshit parents. And for this kind of thing, how would you even enforce it?

          • ramble81@lemmy.zip
            link
            fedilink
            English
            arrow-up
            42
            arrow-down
            1
            ·
            7 days ago

            That’s the issue. We don’t need nanny’s to age gate us on the internet. All it does is create a very short path to removing anonymity on the internet

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              39
              ·
              7 days ago

              Don’t mind some age gating tbh. It would have to be pretty convenient and anonymous though.

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  22
                  ·
                  edit-2
                  7 days ago

                  Well the implementation is going to be that you prove your age to the id app that only saves the info that you’re over 18. Then the id app just tells that info to the website (or app or whatever I guess). So the site doesn’t know who is trying to prove their age or even what their age is, just that they’re over 18.

                  It would be nice to have that sort of quick and easy app for verifying your personal information too. I don’t think we have one where I live. We always use a bank for that and that’s more hassle than I’d like

                • Dnb@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  arrow-down
                  15
                  ·
                  7 days ago

                  Easy. You set the age in the os (or age range) per system account.

                  Apps can then request this and allow/ deny based on it. Requires admin / sudo to update age range.

                  No need for 3rd parties, id or anything else.

                  If parents are concerned about it they can implement it easily. If not, they can ignore it.

            • LwL@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              2
              ·
              6 days ago

              Should supermarkets just sell alcohol to 10 year olds?

              I think there are plenty of places where age gating makes sense as a concept, it really is mainly the data security that’s an issue. The other is that it should be somewhat circumventable, which I think mainly requires it not being tied to identity (so much like you could get someone older to buy you alcohol you could get someone else to verify your age).

              What I think is bad is age gating social media instead of doing something about how harmful it is because clearly adults are not immune and all that does is make it harder for children to get important information.

              • muusemuuse@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                6 days ago

                Yes, alcoholism is a huge problem is 10 year olds. We better focus on that instead of literal pedophiles on Roblox.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                6 days ago

                I’m not talking about that… I agree that you can’t sell alcohol, or cigars, or anything like tat, to children.

                But there’s a difference between that and online content.

                I didn’t said age gating was bad in alll contexts, but that age gating information, media and content is bad.

              • lightnsfw@reddthat.com
                link
                fedilink
                English
                arrow-up
                13
                ·
                6 days ago

                Yeah, that’s why you monitor what the kids you’re responsible for are doing on the internet. It’s trivial to setup parental controls on a network.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                English
                arrow-up
                9
                ·
                edit-2
                6 days ago

                Hell naw, that’s an arbitrary take. There’s no “child things” or “adult things”, nor “male things” or “female things”, just things, and the “male”/“female”/“child”/“adult” is an arbitary tag we put on them.

                And even if there are some things that aren’t so good for the child to see, the only correct way to address that is educating them, guiding them, listening to them and, over all, treating them as humans, the “we need to block this to children” is totally adultist.

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  8
                  ·
                  6 days ago

                  And even if there are some things that aren’t so good for the child to see

                  That’s what people mean by “not all stuff is for kids”

              • merc@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                5
                ·
                6 days ago

                Maybe, but that doesn’t matter since automated age verification doesn’t work. Kids always figure out ways to bypass it, and it snares unlucky adults all the time.

          • Doomsider@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            ·
            7 days ago

            I think no ASL covers it for the Internet. Going against the most basic rule is kind of ridiculous.

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              18
              ·
              7 days ago

              If it’s going to be implemented imo it’s better to do with a privacy respecting centralized fashion than sending your id pics all over the place

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  15
                  ·
                  7 days ago

                  You can protect the identity and all other info of the person than if they’re over 18 or not. I think that’s a lot better than the other ways sites are now using.

                  Unless you think it of just as bad because a site knowing if you’re 18+ is a violation of privacy, so might as well give them everything haha

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          23
          ·
          6 days ago

          They’re already doing the verification and it’s not going away. I definitely prefer a better way to do it

          • Kangae_Hishiryo@scribe.disroot.org
            link
            fedilink
            English
            arrow-up
            37
            arrow-down
            1
            ·
            6 days ago

            That “it’s not going away” attitude is the fucking problem…

            We should fucking fight it, either by good or by bad, because that defeatism is what they want, they want us to think that TINA, then, little by little, force ourselves to do things that at first would seem unacceptable to us.

            • Saapas@piefed.zip
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              17
              ·
              6 days ago

              But in this case there’s already a lot worse system in place. Why not get a better system while also fighting the verification thing?

              • lightnsfw@reddthat.com
                link
                fedilink
                English
                arrow-up
                16
                ·
                6 days ago

                No, get rid of the bad system and be done with it. No compromise. This isn’t something that needs to exist at all.

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  5
                  ·
                  6 days ago

                  I sincerely wish you luck in your endeavor, but I’m not very optimistic about it so in the meanwhile, better system would be better

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  2
                  ·
                  edit-2
                  6 days ago

                  I mean I’d rather get crumbs than nothing? lol

                  Just seems pragmatic to me

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  6 days ago

                  Wouldn’t that be the best system? This system is a lot better but better just means better than the other thing

                • Saapas@piefed.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  2
                  ·
                  6 days ago

                  I’m pretty indifferent to there being age gates. I hate the shitty implementation though, I’d never sent my id to random sites

      • ayyy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        6 days ago

        That…doesn’t work. Just because you saw one dumb YouTuber say something doesn’t make it true.

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          2
          ·
          6 days ago

          I’m not sure if there’s some popular video you’re talking about but I’m talking about the EU ID proposal. Haven’t seen any videos about it

        • Saapas@piefed.zip
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          19
          ·
          edit-2
          7 days ago

          Have the app you use to verify scan it so it can sanitize it

  • sunbytes@lemmy.world
    link
    fedilink
    English
    arrow-up
    41
    ·
    6 days ago

    The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.

    It is the only way we can we safe.

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    118
    ·
    7 days ago

    Also it doesn’t help that, for example, at U-Haul, employees just use their personal phone to scan a QR code and take pictures of your ID.

  • dan1101@lemmy.world
    link
    fedilink
    English
    arrow-up
    95
    ·
    7 days ago

    I don’t like it when a store scans my driver’s license to buy alcohol. I stick to small convenience stores without that tech.

    • boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      15
      ·
      edit-2
      7 days ago

      Had a fun time visiting the US, clerk didn’t understand why she couldn’t scan my ID and find it in the database. All that for trying to buy some cigarettes as I was a smoker at the time and didn’t bring much with me (stupid mistake, they’re way more expensive in the US)

  • 0x0@lemmy.zip
    link
    fedilink
    English
    arrow-up
    25
    ·
    6 days ago

    I bought a domain, configured the webserver in the next 5m.

    As soon as it started taking requests (on a domain that i haven’t even announced yet) it got flooded by bots.

    • Brimstone@lemmy.ml
      link
      fedilink
      English
      arrow-up
      18
      ·
      edit-2
      6 days ago

      Yeah I worked for company with publicly exposed server, the logs were amazing.

      Just bots scanning default ports trying default username and password for services like Microsoft SQL server.

      It’s such a waste of energy really

      • edgesmash@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        6 days ago

        That’s been happening since forever, though. I helped manage proxy servers for my first job in the mid 00’s, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.

    • ddplf@szmer.info
      link
      fedilink
      English
      arrow-up
      9
      ·
      6 days ago

      If your browser is based on chromium, you’re employing an army of bots yourself that gets enabled each time you enter any domain.

    • 0xDREADBEEF@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      5 days ago

      Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/

      Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn’t get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.

      You can use something like crt.sh to look up domains

  • Bell@lemmy.world
    link
    fedilink
    English
    arrow-up
    51
    arrow-down
    2
    ·
    6 days ago

    Annnd this is why a refuse to verify with IDs online and use services like Plaid. And the web of T&C’s from multiple 3rd party services like this will mean all of them get shielded from blame.

    • 7101334@lemmy.world
      link
      fedilink
      English
      arrow-up
      31
      ·
      6 days ago

      Did you read the article? They were renting a car. A car rental place isn’t going to let you just not show your ID.

      • ikidd@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        23
        ·
        6 days ago

        So how they did it once upon a time was you showed them your license, they punched the # into the system that would check it. The person at the desk would confirm it was you from the picture. No need to scan the actual ID card, which is where this problem comes from.

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        6 days ago

        Yeah, it was from renting cars, but they are digital copies of your ID, so any online service is just as “at-risk”, if not more.

    • Raiderkev@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 days ago

      The IRS made me since I used a different service to file my takes this year. It was a pain in the ass. Apparently my existing id.me login wasn’t enough, they wanted a video call or a scan of my face. There was no other option. It was a pain.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 days ago

        they tried that with me. I just told em to fuck off.

        if you make it impossible to identify myself through standard means, you don’t get my tax dollars. 🤷 fuck em.

  • Hikermick@lemmy.world
    link
    fedilink
    English
    arrow-up
    43
    ·
    6 days ago

    My elderly father recently fell for a Facebook imposter that pretended to be a family member and asked if their friend could contact him. The friend asked him to take a photo of his driver’s license and text it to them, fortunately he doesn’t know how. I’ve been wondering ever since what can they do if they had it? It doesn’t have his social security number on it. His credit has since been locked and banks notified

    • GenosseFlosse@feddit.org
      link
      fedilink
      English
      arrow-up
      26
      ·
      edit-2
      6 days ago

      They can open bank or crypto accounts in his name, and then either overdraw the account or use it to move money from other scams in and out of this account, so the real scammers name is not attached to this account.

      • aceshigh@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 days ago

        Is there a way to block that? Ie: freezing your credit means no one can take a loan, but that doesn’t remove the scenario you described.

    • historicaldocuments@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      ·
      6 days ago

      I’ve been wondering ever since what can they do if they had it?

      Ask for pictures of all his other paperwork so they can finish onboarding him at his new job.

      • ChexMax@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 days ago

        I’m sure in the hour long to read rental agreement you don’t have time energy, or the law degree it takes to understand, you waive your right to any lawsuit and have already agreed to settle out of court.

    • Zitronenlolli@thelemmy.club
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      In addition to scanning and verification, VeriScan performs ID parsing to collect, separate, and classify information from the various fields on IDs. This allows Planet 13 to seamlessly harvest the names and demographic/geographic information of its guests. This data is providing insights into customer profiles, which is especially valuable as Planet 13 expands its footprint into other states, including supplementing its SuperStores with smaller, neighborhood retail shops.

      I have no words.

  • Horsey@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    6 days ago

    Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)

    • Hildegard (she/her)@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 days ago

      The numbers aren’t random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.

      They did change it somewhat recently, but they don’t re-assign the numbers when making that change, so most of the numbers are completely insecure.

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 days ago

      Yeah, we know. We just can’t believe that you actually use it for anything important.

      • Horsey@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.

  • nanometer1625@thelemmy.club
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    6 days ago

    This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California’s virtual driver licenses rotate each 30 days.

    • Funkt4st1c@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 days ago

      We honestly should be using virtual vouchers for everything. The question then becomes “whats one level up from the voucher i can steal” and we’re very frustratingly (for my mental exercise) back at square 1

    • Tiral@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      ·
      6 days ago

      Yeah, there’s like 150 million IDs and licenses. I guess the company that handles like every major businesses ID verification has online security designed by Grom. Should arrest the top 15 people hands down.

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 days ago

      Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.