▲ 427 ▼ EU age verification app can be hacked in 2 minutes, claims security expert (cybernews.com) submitted 5 months ago by throws_lemy@lemmy.nz to c/technology@lemmy.world 31 comments fedilink hide all child comments
[+] username_1@programming.dev -15 points 5 months ago* (last edited 3 months ago) (6 children) [deleted] permalink fedilink source hideshow 6 child comments replies: [–] Twongo@lemmy.ml 17 points 5 months ago (5 children) lol are you implying security experts should not probe this and we just let it happen? permalink fedilink source parent hideshow 5 child comments replies: [+] username_1@programming.dev -3 points 5 months ago* (last edited 3 months ago) (4 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Twongo@lemmy.ml 7 points 5 months ago (3 children) that is a very pessimistic outlook. there covid app for example was also something that could be misused in terrible ways and they managed to even get it approved by the ccc. defeatism just makes things worse. permalink fedilink source parent hideshow 3 child comments replies: [+] username_1@programming.dev 0 points 5 months ago* (last edited 3 months ago) (2 children) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent [–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent
[–] Twongo@lemmy.ml 17 points 5 months ago (5 children) lol are you implying security experts should not probe this and we just let it happen? permalink fedilink source parent hideshow 5 child comments replies: [+] username_1@programming.dev -3 points 5 months ago* (last edited 3 months ago) (4 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Twongo@lemmy.ml 7 points 5 months ago (3 children) that is a very pessimistic outlook. there covid app for example was also something that could be misused in terrible ways and they managed to even get it approved by the ccc. defeatism just makes things worse. permalink fedilink source parent hideshow 3 child comments replies: [+] username_1@programming.dev 0 points 5 months ago* (last edited 3 months ago) (2 children) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent [–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent
[+] username_1@programming.dev -3 points 5 months ago* (last edited 3 months ago) (4 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Twongo@lemmy.ml 7 points 5 months ago (3 children) that is a very pessimistic outlook. there covid app for example was also something that could be misused in terrible ways and they managed to even get it approved by the ccc. defeatism just makes things worse. permalink fedilink source parent hideshow 3 child comments replies: [+] username_1@programming.dev 0 points 5 months ago* (last edited 3 months ago) (2 children) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent [–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent
[–] Twongo@lemmy.ml 7 points 5 months ago (3 children) that is a very pessimistic outlook. there covid app for example was also something that could be misused in terrible ways and they managed to even get it approved by the ccc. defeatism just makes things worse. permalink fedilink source parent hideshow 3 child comments replies: [+] username_1@programming.dev 0 points 5 months ago* (last edited 3 months ago) (2 children) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent [–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent
[+] username_1@programming.dev 0 points 5 months ago* (last edited 3 months ago) (2 children) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent [–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent
[–] Jesus_666@lemmy.world 11 points 5 months ago So your argument is that since you are opposed to the app's very existence it's immoral to test it for security flaws. I'd like to argue against that with the principle of defense in depth. I'm also not a friend of OS-level age verification and would like it to be dropped. But if it is implemented I want it to be implemented in a way that isn't wildly insecure. I can simultaneously argue against the principle as a whole and insist that any implementation of it be secure. If it does come I at least want the damage from a botched implementation to be mitigated. To use your cage analogy, I can both complain about the principle of caging people and about the fact that the cage is badly made and poses an injury risk to the people inside it. Neither is acceptable. permalink fedilink source parent
[–] Twongo@lemmy.ml 4 points 5 months ago you are missing the point: this measure is a steaming pile of dogshit. but it'll be forced on us anyway - the least we can do is make sure it's at least secure because even a hardliner can't defend this security issue permalink fedilink source parent