Post #3022072
2026-06-01 12:18 UTC
Replies (18)
-
@shadowwwind@mastodon.social 2026-06-01 12:21
@mullvadnet@mastodon.online that's stupid
-
@ananas@scicomm.xyz 2026-06-01 12:25
@mullvadnet@mastodon.online It's really hard to talk with laypeople about this, since every time somebody will start talking about ZKP as if it already was a thing since the documentation is written in a way that presupposes it.
-
@crazyeddie@mastodon.social 2026-06-01 12:58
@mullvadnet@mastodon.online So I'm trying to learn zkp right now and it seems to me that it doesn't do much. For example, to generate a proof to verify age you need both the actual birthday and the target age. So you can't just certify a proof that can be used with any age. You have to certify ones that are for say 21 and 18 and any other you might need. So far that's what I'm seeing and that seems useless to me. You can just certify a statement that says, "This person is 18," and forego all the math.
-
@leo@gts.heitmannruiz.org 2026-06-01 13:01
@mullvadnet@mastodon.online the post says the california bill "will require identity verification at the operating system level starting in January 2027", but the article you link says "users simply declare their age". that's clearly not "identity verification", right? am i missing something? https://mullvad.net/en/blog/age-verification-for-social-media-the-beginning-of-the-end-for-a-free-internet#:~:text=require-,identity%20verification https://reclaimthenet.org/california-ab-1043-os-age-verification-law#:~:text=users%20simply%20declare%20their%20age thanks for the (grim) summary.
-
@multisn8@mastodon.catgirl.cloud 2026-06-01 13:05
@mullvadnet@mastodon.online That is abhorrent. Doesn't exactly make it easier that "age verification" (some mechanism of proof) can actually be "age attestation" (enter data yourself), as it's the case in e.g. the California bill: This bill, beginning January 1, 2027, would require [...] an operating system provider, as defined, to provide an accessible interface at account setup that requires an account holder, as defined, to indicate the birth date, age, or both, of the user of that device [...]. see https://blog.giovanh.com/blog/2026/03/22/os-level-age-attestation-is-the-good-one/ ∧ https://blog.giovanh.com/blog/2026/03/22/identity-verification-is-as-bad-as-it-can-be/. I don't think keeping the status quo is politically feasible right now, but we can definitely get an explicit distinction through to go for attestation
-
@light@noc.social 2026-06-01 13:30
@mullvadnet@mastodon.online cc: @taylan@fedi.feministwiki.org
-
@lumi@snug.moe 2026-06-01 13:36
@mullvadnet@mastodon.online and it also: - assumes you have a smartphone - uses drm to make sure you only use a google-approved or apple-approved device it's honestly awful, and them calling it "open source" is misleading. you can't effectively fork it yourself or make your own implementation
-
@hsza@social.tudbut.de 2026-06-01 13:41
@mullvadnet@mastodon.online the very concept of age verification is a fascist surveillance fantasy, and were it implemented in a perfectly secure and zero-knowledge manner that would still be the case. the very notion must be fought i hope this is understood
-
@kemra102@mastodon.social 2026-06-01 14:18
@mullvadnet@mastodon.online Please re-consider referencing "Reclaim the Net" - they are clearly from the article you linked far right free speech absolutists who are pro hate speech. Free speech MUST have limits, and that limit is hate.
-
@isomoth@infosec.exchange 2026-06-01 14:26
RE: https://mastodon.online/@mullvadnet/116674808630304817 "It will be interesting to follow the countries that pursue system-level control as they move further down the slippery slope toward open-source systems. Since open-source systems cannot be controlled, politicians would ultimately need to ban devices that are not controlled by the state. The end point: telescreens like those in Orwell’s 1984, devices that both monitor you and broadcast only the information approved by the state."
-
@benjistokman@mast.benstokman.me 2026-06-01 17:24
@mullvadnet@mastodon.online it's not cryptographically possible to have such a system anyway. You can always just check against each person's certificate or similar to deanonymize them
-
@usernomnomnom@mastodon.social 2026-06-01 17:38
@mullvadnet@mastodon.online thank you for raising awareness about this!
-
@kaffekod@fikaverse.club 2026-06-01 18:29
@mullvadnet@mastodon.online I just added your atom feed to my reader. Thanks <3
-
@yon@sakurajima.moe 2026-06-01 18:39
@mullvadnet@mastodon.online It’s mass surveillance and that is never good. I don’t trust any anonymizer like this to be honest.
-
@wolnyjez@mastodon.social 2026-06-01 19:59
@mullvadnet@mastodon.online ZKP are just a distraction. Regardless of whether the EU app will use zero-knowledge proofs or not, it certainly won’t provide true anonymity (because if it did, proxy services capable of verifying anyone’s age would appear within a matter of hours). Given the above, it is not hard to see that the real aim is to put an end to online anonymity and to establish state surveillance of everyone’s Internet activity.
-
@project1enigma@chaos.social 2026-06-02 13:42
@mullvadnet@mastodon.online And I'd like to not forget that even if ZKP were always there, built in, no non-ZKP path, there would still be enough reasons to oppose this.
-
@rawenwolf@meow.social 2026-06-02 13:43
@mullvadnet@mastodon.online Considering "meatspace" age check can't be done without an ID check, how do we expect to solve this in online space? ZKP is either a "smokescreen" at best (anyone who has the resources can do the tracing and state actors absolutely have that) and a pointless exercise at worst (if the ZKP token is transferable then it makes the entire system useless).
-
@syllopsium@peoplemaking.games 2026-06-02 14:51
@mullvadnet@mastodon.online system designed as intended