HN user

Mindwipe

1,568 karma
Posts2
Comments1,817
View on HN

For things like movies, they should have negotiated a contract where sold copies are sold copies and cannot be revoked (even if their right to sell/rent copies lapse).

It's difficult to see how this could ever be possible without significant legislation changes. Nobody (but nobody) offers this, and in the vast majority of the world you literally can't buy out music rights in this way for any licensed music in the titles. That's why literally no online store offers this.

The announcement only seems to have been sent to users in the UK and MoviesAnywhere is a US only service. Also StudioCanal are ultimately the rightsholder who would need to join MoviesAnywhere, and they are not members.

(I am a bit surprised they didn't bung Google and StudioCanal a bit of money to move them to Google Play to avoid the bad publicity though.)

The fact this letter takes aim at something the paper doesn't say is pretty damning. The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties, including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with.

Yoti's letter then gets angry that "face" data is not passed to third parties. That is not what is alleged.

Not to mention the repeated veiled threats about how they "could" sue academics investigating their systems.

It is absolutely incredibly sus as a letter.

Individual self employed photographers successfully use the DMCA to get significant payouts from large publishers and news organisations every single day.

Like literally hundreds of thousands, every day.

No there aren't, because having identical builds of games with Denuvo actually removed and present is vanishingly rare.

If you compare a game that's had significant performance patches over a period of years and had Denuvo removed to the launch version (as so many of these videos are) then no shit you see performance differences, but it doesn't tell you anything.

The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody.

No it isn't.

Literally that is not the scope document, and such a solution would not be permitted by the EU as compliant with the legislation.

The app isn't zero knowledge. A prototype workflow has been designed for a one way transfer to sites that is zero knowledge, but it doesn't actually deliver zero knowledge because it you have to verify your age with an external provider to get the credential (which is not zero knowledge), the app has to be secured with either Apple or Google's attestation services (which are not zero knowledge), and the site has to be able to check with the original external provider that the credential hasn't been revoked (which is in no way zero knowledge).

I hate to break it to you but services have been routinely blocking residential IPs associated with being part of VPN endpoints for the better part of a decade now. Akamai will even sell you (granted they are just reselling another vendors product) a database to do this.

The Pro really looks like it's struggling for a reason to exist given how much cheaper this will be and the difference in feature set.

Yes, 100%.

If they wanted the policial platforms and had offered to buy them from Warner as standalone for a tenth of the cost Warner would have snapped their hand off.

They need the IP for scale. That is what this is about.

I'll believe it when I see it. Windows many problems are the results of five years of terrible strategy and not caring about if users actually like your platform. It will require sustained effort over a long period to fix.

Presentation of someone else's valid credentials is not fixable by any privacy-preserving mechanism.

And that is precisely why governments will never implement a privacy-preserving mechanism, which is exactly my point.

Compromised tokens would be trivially google-able within a day otherwise.

The EU Digital Identity Wallet isn't zero knowledge. I mean it's just not. It relies on Google Play Integrity Attestation on Android and the iOS equivalent on Apple devices because those give it a revocation mechanism, and those aren't zero knowledge.

https://github.com/eu-digital-identity-wallet/av-doc-technic...

It says that it wants to be zero knowledge, but it has no zero knowledge implementation and no plan of how it even possibly could be zero knowledge, and it never will precisely because that is incompatible with the revocation requirements set down by the EU.

I mean the main reason it exists is because. Nvidia spent a bunch of money designing and fabbing the Tegra for automotive use and nobody bought it so the project was desperate to find a customer rather than out of the goodness of their hearts. That's also why they sold it to Nintendo at a bargain basement price for the Switch.

I strongly suspect the reality is that they had to give Nintendo so much money back due to the complete failure of the bootloader security that they still produce the Shield as Jensen still demands they claw their way back to break even.