HN user

truthfinder61

1 karma
Posts0
Comments5
View on HN
No posts found.

Hey Mindwipe, 100% agree the paper doesn't say that face data is passed to third parties, but then the techexplore article from those universities DOES. That article is the one that this whole thread started on, strangely you are ignoring that.

What's pretty damning is that you make it appear like you know the paper but you claim things that the paper doesn't claim. In the exact same style of those who wrote the article, interesting.

You claim that "The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties"

That is FALSE, the paper doesn't say that, it actually says that the high entropy metadata is sent to Yoti servers, actually encrypted with client side keys on top of TLS which makes it impossible for any third party to even read it.

Reporting here extract from the paper: --- Once the user’s face is properly aligned, the SCM collects and processes a significant amount of data that is sent to Yoti’s servers. In particular, it collects the photo captured from the user’s camera and telemetry, including significant high-entropy browser and device metadata (see Table 2). It also includes data about the camera’s properties, the FPS of the camera stream, and metrics about download and processing times.

The SCM uses some cryptography, which we briefly describe here before returning to its implications in Section 5.5.3. If the image encryption setting is enabled (as it is by default), the SCM encrypts the captured image using AES-GCM with a key and initialization vector (IV) derived in the browser. Similarly, the telemetry and metadata collected is also encrypted under AES-GCM in the browser. ---

Then you claim "including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with."

Which perfectly highlights the issue, as it seems like you might have gotten that from the Abstract section of the paper.

The great thing is that the paper itself disproves all of that when you read all the details. And anyone can find out that the key section where there is actual sharing of data with third parties (not the visiting site) is when the credit card check method is used for example. Which is pretty inevitable, to do a credit card check you need to use a payment provider which will have to process the data necessary to do that.

You have to read the paper (which in itself is quite speculative), but it never says that Yoti is broadcasting face images or ID document images to third or fourth parties. The paper analysed this Yoti platform that allows Company A to decide which age verification methods it wants to offer to their end users. These methods go from age estimation, ID document check and also old school credit card check.

Now credit card check to confirm someone's age is something that existed since ever, and it can only be done by interacting with a payment provider (which is the claimed third/fourth party in the paper) and I can assure you that no one gets paid by the payment provider so you can check a credit card, actually you have to pay them a fee. So in this case Company A is paying a fee to Company B that is running the age check and Company B has its own costs like paying the payment provider a fee to conduct the credit card check. Company B doesn't get paid by anyone else other than Company A, there is no bribe man.

You can clearly see the bias and political intention behind all of this, see also how they use the word "broadcasting" which has a very specific meaning (broadcasting is the distribution of something to a dispersed public audience) which is not what the paper is claiming, there is no broadcasting, any payment provider requires authenticated private and secure connection.

When it comes to the age estimation method and ID document, the paper does not claim that any of that is shared with third parties, as by tracking the network traffic it can see that it goes directly to Yoti. Yoti itself claims and audits his system to prove that any of the personal data they process never leaves their system and is immediately deleted as soon as the age check is done.

The reality is Company B has nothing to gain by keeping or sharing people's data because all they do is based on Company A trusting them and any risk that destroys that trust is unacceptable.

What this political campaign is doing is trying to cast doubts on that trust with lies. So that people like you go and do the campaign for them.

Yoti is being so heavily attacked because they proved that this can be done following high privacy standards, which annoyed quite a lot of people (think the big porn operators for example, which wouldn't be surprising if they are also donors for those privacy groups). It is all about money. If those privacy groups cared about your privacy they would be talking about Google/Apple that know everything you do, anywhere you go, any website or app you use, they even have your biometrics (they say on your phone sure). But as US companies they are obliged to share any data with the US gov if requested and can't tell that to anyone if they ever got that request.

Can you explain what is the bribe here?

Company A hires company B to offload the burden to do age checks, company B takes the burden to do it securely and only returns an age result to company A (no personal identifiable information).

Company A here could be any site, they are good at creating content, they should not be processing sensitive data. Company B is the expert, their job is to process personal data, confirm age, destroy data.

We are definitely entering the era of stupidity. Who wrote that article hasn't read the paper, just asked some AI to scan it and fudge up an eye catching article. The article claim things that are not in the paper, that are actually false, the paper does state the face image is actually encrypted on the client side and never says that is shared with third parties. If you prompt your AI with enough bias and ask it to read a technical paper, then this is what happens. And given no one bothers to check facts there you go, everyone screaming against a legit company that is just doing its job. The paper itself reports that Yoti has given an amicus brief in a US court where they just stated that age verification can be done in a privacy preserving way (which seems to be what they do, they have nothing to gain from keeping data). I wonder if that is why they are after Yoti so badly now.