Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning.
Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning.
There is a security researcher called Celeste, just like meee! Weirdly enough, that makes me happy 
"""
Persona’s exposed code compares your selfie to watchlist photos using facial recognition, screens you against 14 categories of adverse media from mentions of terrorism to espionage, and tags reports with codenames from active intelligence programs consisting of public-private partnerships to combat online child exploitative material, cannabis trafficking, fentanyl trafficking, romance fraud, money laundering, and illegal wildlife trade.
Once a user verifies their identity with Persona, the software performs 269 distinct verification checks and scours the internet and government sources for potential matches...
"""
So to keep kids safe from online predators, we're willing to *horribly* invade their privacy and sell all their data to predators? I see the system is working as intended 😮💨
@martinvermeer @tootbrute @alice @evacide well #discord always has been garbage and #KYC is always bad!
@[email protected] @[email protected] That's why *"#KYC IS THE ILLICIT ACTIVITY!"* - I mean, there's a [*trivial bypass*](https://www.youtube.com/watch?v=5LsF4FF6gO4) but #Discord itself is garbage!
@alice @evacide i juste read and article by @Ivovanwilligen about persona and if he doesn't know about all this well now he does !
His article : https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/
@evacide Ah yes, "let us protect children by scanning their faces". What could possibly be wrong??? 🤡
“the software ‘flags you as a “suspicious entity” based on your face alone’ …”
Yay! Phrenology 2.0!
@evacide and meanwhile the Australian government is claiming credit for protecting children by standing up to social media companies to force them to use this kind of tech.
I’m sure the pressure is in the opposite direction.
@ollicle @evacide Yep. It's brilliant from a certain perspective. Horrifying, sinister, but with a certain genius.
The tech firms get to say "Oh, no, the horrible government is making us do this. Oh well. Now give us your identity documents."
The governments get to give the appearance of responding to (genuinely) grieving parents, and say "we're protecting the children" which is game over for any alternative voice. All the while receiving funding (directly or indirectly) from the tech firms that created the problem or the supposed solution, or their fellow travellers.
And parents get to believe their children's safety is taken care of.
@evacide l, “they took the most powerful communication technology in human history and turned it into a slot machine that makes you sad. We're all rats in a skinner box pressing the lever for pellets of validation.”
Yup
This level of centralisation of data is so so dangerous. Putting all our eggs in one basket digitally makes for a very inviting target, but this sort of infrastructure also concentrates power.
Knowledge is power, and this level of control can easily calcify our political systems and eat away at democracy.
@evacide if something is free, never forget to ask who pays for it, who benefits?
I personally think it's great, though, that there are also people striving _for_ a better internet. That gives me hope. 🙂
@evacide
One of the many reasons to be against #ageverification software
It gives the wrong people & companies tons of data, often #biometric ones
Therefore we transfers #power exactly the wrong people & #corporations
And as we can know latest since #Edwardsnowden companies do share data with governments
The cornerstone of the #chinese #surveillance #state is #realnameregistration
Don't give #biometrics to #evilcorp, especially not for cheap thrills
Do not hand data to #fascists
@[email protected] @[email protected] That's why *"#KYC IS THE ILLICIT ACTIVITY!"* - I mean, there's a [*trivial bypass*](https://www.youtube.com/watch?v=5LsF4FF6gO4) but #Discord itself is garbage!
I am noticing a pattern that security for unethical companies appear to have strong vibe coding traits