mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.5K
active users

#identification

1 post1 participant0 posts today
Y⃒̸̷̝̜̙ͥͥͥngmar<p>Food or stomach pain?</p><p><a href="https://social.tchncs.de/tags/Mushroom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mushroom</span></a> <a href="https://social.tchncs.de/tags/Identification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Identification</span></a> <a href="https://social.tchncs.de/tags/Lithuania" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lithuania</span></a></p>
Freezenet<p>UK Residents Now Creating Fake IDs to Circumvent Age Verification</p><p>The protest against the UKs Online Safety Act is only continuing to grow with some now creating fake IDs of MPs to circumvent age verification systems.</p><p><a href="https://www.freezenet.ca/uk-residents-now-creating-fake-ids-to-circumvent-age-verification/" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">freezenet.ca/uk-residents-now-</span><span class="invisible">creating-fake-ids-to-circumvent-age-verification/</span></a></p><p><a href="https://noc.social/tags/Censorship" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Censorship</span></a> <a href="https://noc.social/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a> <a href="https://noc.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> <a href="https://noc.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://noc.social/tags/AgeVerification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AgeVerification</span></a> <a href="https://noc.social/tags/britain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>britain</span></a> <a href="https://noc.social/tags/ID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ID</span></a> <a href="https://noc.social/tags/identification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>identification</span></a> <a href="https://noc.social/tags/UK" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UK</span></a></p>
Replied in thread

@BackFromTheDud @skinnylatte @minmi

BTW, an interesting POV I learned from Tendayi Bloom, a scholar and editor of the book below (disclosure: of which I am a contributor), is that while #homelessness itself is usually not illegal, the practise of making #natural #human #necessities such as sleeping and excreting waste illegal in public spaces has the same effect as #criminalising being #unhoused.

😡

I am linking the book because there are so many vectors to being treated as non-#citizens that I think it are important to be aware of, even if one is *technically* a citizen, claiming such rights may depend on a number of other systems such as #authenticated #identification to "enjoy" those rights.

Lots of complexity that absolutely could be fixed if policymakers chose to do so. 😡

manchesteruniversitypress.co.u

#criminalisation
#citizenship
#HumanRights
#dignity
#access
#accessibility

Manchester University PressManchester University Press - Statelessness, governance, and the problem of citizenshipStatelessness, governance, and the problem of citizenship - Browse and buy the Hardcover edition of Statelessness, governance, and the problem of citizenship by Tendayi Bloom
Replied in thread

@LukefromDC : it won't be that bad (it will be bad, but in a different way).

ANY website may ask a user to confirm they are 18+ (or whatever age).

There will be a huge amount of AitM (Attacker in the Middle) websites where naive people will be lured to (using fake emails, SMS, chat app messages or falsified QR-codes) and asked to confirm their age.

That AitM website will subsequently obtain a "ticket" (session cookie) from a real "relying party" website (with a potentially very different type of content than the victim is told).

Those "tickets" will be sold (or traded for watching ads and/or paying with privacy).

Reliable authentication requires a trustworthy identity verifier (even if identification is restricted to age+).

@drgroftehauge @fabio @SylvieLorxu

Replied in thread

@jwildeboer : modern certificates are used for authentication only, not for secure connections.

OTOH, if you have no certainty that your software is communicating with the server you intended, a secure connection to it is pointless - but the connection remains secure.

Using TLS v1.3, the connection is even secured before the server is authenticated (if, after encrypting the connection, the authentication of the server fails, then the client should at least warn the user - if not immediately disconnect).

Yes, I know, these are boring details, but they are misunderstood way too often by people who SHOULD know how this works (I know you do, but please don't simplify things too much).

#TLS#https#X509
Replied in thread

@adfichter : I'm trying to warn people for such holes.

Published earlier this month: heise.de/en/news/BSI-and-ANSSI (there of course is a German version as well).

It refers to a recent joint publication (in English) by the German BSI and the French ANSSI titled:

"Remote ldentity Proofing for EUDI Wallet Onboarding: Strengthening Assurance Against Evolving Threats"

(EUDI Wallet = European Digital Identity Wallet aka EDIW aka EUDIW).

It's about the risks of VideoIdent (getting bigger every day, see e.g. theverge.com/report/714402/uk- - not to mention AI).

However, like in their previous publication (PDF: bsi.bund.de/SharedDocs/Downloa) they ignore one HUGE risk: AitM's (Attacker in the Middle).

The unmentioned gaping security hole here are fake websites, where people are being directed to via falsified emails, SMS, chat app messages and possibly QR-codes.

Step 1️⃣:
————
Victim (contacts AitM site as instructed)
|
| "Please give me my EDIW"
v
AitM site: contacts site below and forwards
|
| "Please give me my EDIW"
v
True EDIW identity verification site

Step 2️⃣:
————
Victim
^
| "Please perform VideoIdent"
|
AitM site: forwards
^
| "Please perform VideoIdent"
|
True EDIW identity verification site

Step 3️⃣:
————
Victim
|
| VideoIdent showing victim
v
AitM site: forwards
|
| VideoIdent showing victim
v
True EDIW identity verification site

Step 4️⃣:
————
Victim
^
| "Something went wrong"
|
AitM site: stores victim's EDIW on their device
^
| EDIW
|
True EDIW identity verification site

The same may happen to people who are tricked into *authenticating* using EDIW on AitM websites.

@ellent

heise online · BSI and ANSSI warn against VideoIdent for the EU digital walletBy Stefan Krempl
#EDIW#EUDIW#AitM

Son bec serait plus petit en hiver ? Oui c’est vrai !
Quand il n’est pas en plumage nuptial, le macareux moine présente un bec plus petit et aussi moins coloré…
Pourquoi cette différence ? Il est probable que la taille et la couleur du bec jouent un rôle dans la séduction, un caractère sexuel secondaire favorisant la reproduction. Mais cette théorie, bien que plausible, reste encore à confirmer par les scientifiques…
#macareux #aquarelle #dessinnaturaliste #ornithologie #arctique #illustration #identification #dessin #oiseau #artiste

click.actionnetwork.orgUnmask ICE. No Secret Police in America. In cities and towns across America, masked Immigration and Customs Enforcement agents are kidnapping people off the streets while hiding their own identities and ignoring constitutional rights like arrest warrants and due process. This is what happens in authoritarian societies. Law enforcement officials must not be allowed to hide their badges and identities when making arrests. Identification on uniforms must be required. Officers must be unmasked. In response to these authoritarian tactics, elected leaders in California have introduced a bill that bans all law enforcement officials from using masks and requires ICE to provide clear identification on their uniforms during arrests. Congress and legislatures across the country should do the same. There should be no secret police in America. Demand action to unmask ICE by adding your name now.
Replied in thread

@aral wrote: "If your friends and family are trying to phish you, you have bigger problems."

Phishing means that an adversary *claiming to be* someone you know (including friends and family) convinces you to click on a link.

The purpose of a certificate, telling a receiver *WHO* (human readable) owns the associated private key (the last resort to distinguish between fake and authentic), now has completely vanished.

As if phishing is not already the nr. 1 problem on the internet.

Note: I'm fine with the idea provided that browsers clearly inform users about the reliability of authenticity (I've read your article, did you read infosec.exchange/@ErikvanStrat ?)

@letsencrypt

Infosec ExchangeErik van Straten (@ErikvanStraten@infosec.exchange)Content warning: (long) Wrong order: RPKI first - WebPKI never?