The web around the late 90s and early 2000s had some really sketchy stuff. I think the difference is that it used to be the sleazy underbelly. Now it's accepted as mainstream.
My local 'newspaper' website is chock full of scam adverts. The print version is dignified. The website people, somehow, turn a blind eye.
And I got an advert on Youtube this week using sexually explicit language to sell pills.
Feels like standards, and expectations, have really slipped.
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
This is the correct intuition. The problem can be solved with antitrust by forcing hardware vendors to ship their devices without an operating system. Then the market will deliver the parenting solutions that don't require mass surveillance. We're currently being blocked from doing so by anti-competitive measures.
Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
They already regulate the amount of rain water you can collect, or how much water you can take from your own well, or how many solar panels you're allowed to use
You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
What do you expect - the EU to centrally plan a phone OS? They are capitalist with regulations, you know, not communist. Someone has to actually make one themselves.
Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share.
Now that would be pretty good. I thought there was already an unlockable bootloader mandate but it seems I was mistaken. Most phone makers openly violate GPL and don't get punished, too.
Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale.
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
I literally lol'd at the "Most analysts expect..." line.
Yea, most analysts didn't expect the cookie banner nightmare we're living in either.
To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse.
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use.
We use that approach in several other industries.
But.... that requires work beyond just complaining.
>But.... that requires work beyond just complaining.
So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to.
The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care.
For the people who care, it's not a matter of work, because they don't operate the platform.
> You can of course create an independent attestation database at any time
Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
Come on now.
> minimum security requirements for digital ID use
Also known as "the user has no control over the device".
Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.
> We use that approach in several other industries.
Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
> Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
That sounds mostly like copium just to motivate your complete inaction.
Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU.
But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.
> Why not tell us more about the requirements for hardware certification?
Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs).
But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment.
>Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux.
> cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM
So it must be secure against the user, as expected.
Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape.
> But sure, it's a all an evil conspiracy against general purpose computing.
You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this.
> Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away.
It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you.
The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive.
It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online.
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
I was horrified by the literal waterboarding scene in Shrek. Granted it was a year or two before the USA started trying to normalise that form of torture. I don’t know what was in the popular consciousness in the US at the time. But it’s very spooky.
Children’s fiction has always had a very dark side though.
Yeah, I think the “adult media disguised as kids media” has been a thing for a long time.
But I also think that a lot of teen and preteen media has very little functional distinction from adult media.
A lot of non-parents don’t realize that the difference between G and PG can be huge. Shrek sounds like it should be something for a 3 year old but it really isn’t. Even without the torture scene it’s immediacy really scary. You have to go with something a lot more gentle than that for young kids.
I think the torture scene is funny to an adult as a mockery of the zeitgeist if you decide to interpret it that way. After all, Farquad is intended to be a villain.
It's been dark since the Grimms, and likely long before!
I just rewatched it (link in sibling link). It's mocking Farquaad, but I think is clearly meant to be taken as slapstick. Implying that torture is no big deal.
Yeah and I guess there are two directions you can go with slapstick like that: “it’s minimizing torture in a disturbing way,” or “all slapstick comedy necessitates suspension of disbelief.”
There is no 'literal waterboarding scene' in the theatrically released Shrek. In the scene you've seen, unless you're deep into dubious fan-remakes, Gingy 'just' gets dipped in milk (mostly off-screen) by an executioner-style heavy, then Lord Farquaad taunts them with their torn-off legs, which suggests legs-first dipping, not the head-first submersion that is the entire point of waterboarding.
Still pretty bad (even though the gingerbread buttons were apparently spared), but... not literal, and not even figurative, waterboarding.
At the opening of the scene, the gingerbread man is being drowned in milk. You see from the shadow, and the voice, that he's having his head submerged in liquid. then Lord Farquaad says "enough! he's ready to talk". So that's simulated drowning as part of interrogation to get information.
Nit-picking about the exact _orientation_ of the victim, and therefore what type of simulated-drowning torture this constitutes, is somewhat missing the point I was trying to make! i.e. that torture is normalised to the point of being slapstick in a children's film.
You think they did math on this? No, all he did was have a tantrum where they got attention to themselves and patted themselves on the bat for doing something.
They didn't think through the ecological results of someone scraping off the destroyed concrete and pouring more.
I don't think these ideas are as toxic to the current political climate as you think they are. We're probably just a few short years away from the current generation of right-wing populists integrating ideas like "children are useless eaters that are your property to command, make them give back from all that you gave to them" and "work safety and environmental regulations are an emasculating evil, real men want to breathe poison and take risks" right into the core of their platforms.
Are we talking about the environmental impact? Or are we talking about the vandalism perpetrated by activists? Attention on the protestors is not necessarily attention on the protestors' cause.
I mostly see commenters quipping about how this will just mean the concert will have to be re poured, resulting in yet more emissions. The bulk of the comments are about the protestors, not the environmental impact of this data center.
It's literally a building that turns electricity into reasonably intelligent text and we're still here talking about environmental impacts. Is this where we're at with NIMBYism in the West now? Will there ever be popular support to build industrial production any more?
The Jeff Bezos boat would probably appeal to this crowd, although it is by not remotely miniature.
reply