Hacker News new | ask | show | jobs
by tikkabhuna 18 days ago
Why would an age verification app need to know your ethnicity/religion?

Governments likely already know your name, age, place of birth, so having an app with a standard API for verifying users isn't giving the government additional data.

4 comments

It is one extra attack vector. There is a data leak reported every week, and it is now apparent we cannot trust any organization to handle any datum securely, at all. It has gotten to the point where I now consider every piece of information compromised and sold on the dark web as soon as I am forced to transfer it to a third party. Because those are the odds.
It's also replacing all the personal information stores from thousand applications and websites you have previously registered, or would have to. So arguably it's thousand attack vectors less.
Doing absolutely everything useful with that data is "one extra attack vector". That is not any kind of a persuasive argument in itself.
It may not record your ethnicity or religion, but ID documents certainly record your sex, and plenty of authoritarians seem interested in identifying individuals for whom this database column has been updated.
"government" age verification app will be made and maintan ed by some corp anyways.

so it will gather extra data, sell it sideways and leak like hell. (as they already do with all the data they already have)

Since it requires Android or iOS, Google/Apple can gather the same data too.
They did this from the beginning, still one can not cease trying to limit the exposure.
I'm imagining something like recreation.gov in the US - it's the portal for booking campsites and other activities at national parks. It's run by BAH at great profit - most of the fees we pay aren't going to the national park service, it almost all goes to our corporate overlords.
Governments will track with whom you verify. Much worse.
Can we not spread nonsense narratives? One of the explicit requirements of the EU age verification system is that they cannot:

https://digital-strategy.ec.europa.eu/en/factpages/blueprint...

First, the user downloads the app onto their phone and sets it up by certifying their age. This can be done with a biometric passport/ID card, a national eID (e.g. national ID Card or other electronic identification mean), a pre-installed third-party app (e.g. a banking app), or in person (e.g. at the post office). Only the information confirming that the user is over the age will be saved in the app. No name, no birthday, or any other data is saved.

After completing this step, the communication between the app and the provider certifying the user’s age (e.g. eID, third-party app) ends. No further data is exchanged.

https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verific...

The app will likely have access to a bunch of unique identifiers on the phone. At least on Android whichs core concept is spying on the user.

For me, it's enough that your activity could be linked to any unique identity. I don't want mandatory government apps on my phone, that's very chinese. We should strive for better.

Edited to add: your linked FAQ conveniently leaves open how the communication between the web site and the app happens. There are myriad of ways that ones behaviour leaks in this step.