Readit News logoReadit News
donmcronald commented on Surely the crash of the US economy has to be soon   wilsoniumite.com/2026/01/... · Posted by u/Wilsoniumite
daft_pink · 13 days ago
I think the government is laser focused on reducing regulations, reducing energy costs, reducing interest rates, a weaker dollar that makes exports better, minimizing taxes. Technological innovation is increasing overall productivity. There are definite headwinds like upward pressure on labor by reducing the worker population, stagnating population growth, undertainty, tarriffs, a weaker dollar increasing inflation.

There’s the looming threat of geopolitical world war that has been overhanging the world since the combination of the pandemic isolating different countries and Russia’s invasion of Ukraine.

It’s really a mixed bag, but it’s not clear to me that we are headed into a total economic crash as the government is definitely focused on doing a lot of good things for the economy, but also is creating lots of different headwinds.

donmcronald · 13 days ago
The thing I don’t get is that IMO Americans have a higher standard of living due to demand for the dollar. Being a net importer means they make less and the countries they’re importing from make more. Money = labor = people working, so people in other countries are working harder than Americans to benefit Americans with a higher standard of living.

It’s like a roofer working for a contractor that’s a millionaire and the contractor is upset because he’s paying the roofer while having a higher standard of living because of the profit made off the roofer’s labor.

No one is working for that rich contractor if his money is worthless. Isn’t a weaker dollar for America a disaster? The world works to serve America right now because of the dollar. Life’s going to be tough when America has to “get a job” and start earning their keep with real productivity contributions, isn’t it?

Maybe I’m just dumb, but all I can see is a massive drop in the average standard of living if the US maintains their current trajectory. It might even be too late already.

donmcronald commented on Microsoft forced me to switch to Linux   himthe.dev/blog/microsoft... · Posted by u/bobsterlobster
stackghost · 15 days ago
>no upgrade path to Windows 11 because my CPU was 5 years too old apparently.

Let's be real. It's because new systems support DRM and Microsoft has been captured by the media company lobby.

donmcronald · 15 days ago
It’s way worse than that. It’s for verified identity and attestation.
donmcronald commented on Meta to test premium subscriptions on Instagram, Facebook, and WhatsApp   techcrunch.com/2026/01/26... · Posted by u/andystanton
rwmj · 16 days ago
Top-up subscriptions required for AI features? I wish every service would do this!
donmcronald · 16 days ago
It would be amazing if the tech leadership is so far gone they think AI is so great that everyone will beg to pay for it and it gets locked behind subscription fees. The only way it could get better is if the users that are paying get some kind of flair or label so I can ignore them.
donmcronald commented on House of Lords Votes to Ban UK Children from Using Internet VPNs   ispreview.co.uk/index.php... · Posted by u/donpott
Deukhoofd · 17 days ago
> may make provision for the provider of a relevant VPN service to apply to any person seeking to access its service in or from the UK age assurance which is highly effective at correctly determining whether or not that person is a child

"The law we made is like super duper good!!"

> Children may also turn to VPNs, which would then undermine the child safety gains of the Online Safety Act

"The law we made is easily circumvented :("

donmcronald · 17 days ago
> may make provision for the provider of a relevant VPN service to apply to any person seeking to access its service in or from the UK age assurance which is highly effective at correctly determining whether or not that person is a child

I think you're reading it wrong. Regulations may have a provision that allows providers to apply age assurance [systems ?] if the age assurance is highly effective at determining age.

I'm always surprised how ambiguous the writing is for this kind of stuff. Maybe that's the point. If the regulations don't (may is optional) have the provision, does that mean they need to demand ID?

IMO, highly effective = our buddies' tech that we declare highly effective. The whole ID push around the world is big tech trying to set up government mandated services that you're going to be forced to pay for, either directly or via taxes.

The end game is probably digital IDs with digitally signed requests for everything you do. And, of course, corrupt individuals and criminals will somehow be able to get as many digital IDs as they want.

That money should be spent on education. We're being robbed.

Deleted Comment

donmcronald commented on Microsoft mishandling example.com   tinyapps.org/blog/microso... · Posted by u/mrled
brulx126 · 20 days ago
Not just that, the new outlook app makes Microsoft a complete man-in-the-middle for your email account.

https://www.xda-developers.com/privacy-implications-new-micr...

donmcronald · 20 days ago
They store passwords and proxy everything at the same time they’re pushing OAuth, authenticators, passkeys, etc. for their own services. Everyone should have revolted when they bought Acompli and started doing this kind of thing.
donmcronald commented on CEO of health care software company sentenced for $1B fraud conspiracy   justice.gov/opa/pr/ceo-he... · Posted by u/healsdata
burkesquires · 2 months ago
I think fraudsters should have to work off the money they stole at prison wages…punishments are supposed to be deterent and prevent people from commingting crime…don’t seal a billion dollars becasue IF you get caught you will have to pay back half is not a deterent…BUT if they have to pay off a billion dollars at 13-52 cents/hour…that is a deterent!
donmcronald · 2 months ago
Seize the generational wealth they accumulated. Make their parents, siblings, kids, grandkids, cousins, etc. demonstrate how they earned their money and take every penny they can’t link to honest means.

The discussion around billionaires needs to move away from taxing their income and beyond taxing their wealth. We need to start talking about how much of their wealth we should be taking away. Light it on fire or delete it. The whole world will be better off.

donmcronald commented on Apple has locked my Apple ID, and I have no recourse. A plea for help   hey.paris/posts/appleid/... · Posted by u/parisidau
1970-01-01 · 2 months ago
The untapped answer is litigation. Call a lawyer and file against Apple. It may take several business days, and cost $$$$ but it will absolutely light a fire at Apple and get the attention of many-a-human. And if they ignore it, well, maybe a class action lawsuit awaits.
donmcronald · 2 months ago
I considered this a month or two ago when Google safe browsing was erroneously putting domains self hosting Immich on the block list. My family domain got put on the block list and it took me a few hours to figure out that I needed to sign up for Google Search Console just to figure out what sub-domain got flagged.

I thought about filing a claim for enough to cover my time in small claims court, but decided not to. I didn't track my time super well because initially I though it was my fault, but, by far, the huge deterrent is the "what if".

What happens if I take Google to small claims court for damages to a domain I've been using for 20 years? I have that domain tied to a legacy Google Workspace account which was a huge mistake. It's been tied to my email for at least 15 years and, even worse, I've never owned an Android phone that hasn't been tied to that Workspace account.

I don't depend on cloud services for much, but if I want to prepare for retaliation I'd have to migrate my email somewhere else and be ready to deal with family members that have their phones connected to the Workspace account. Who's been duped into photo "backup"? Who's been duped into using Google Docs? How many Play purchases do they have? And, the big one, who's been duped into using sign-in with Google?

Google, Apple, Microsoft all make choosing what's best for the consumer very high friction compared to choices that trap users and give all the power to big tech. Even though I constantly help my family members try to understand why the don't want to get locked into those services they always get deceived into using them. The number of family members unwittingly duped into uploading all their data to OneDrive is in the range of 100%.

Apple, Google, and Microsoft need to be broken into 10 or 20 companies each. Excel should be it's own company. Phone OSes and app stores should be different companies. OneDrive should be it's own company and to compete with Dropbox with zero Windows integration. The web browsers should be separate companies. The AI divisions should be separate companies. Split them up with a wood chipper IMO.

The safe browsing scam is the biggest fraud ever because providers can't opt out of it when it "accidentally" detriments independent or self-hosted solutions.

donmcronald commented on EFF launches Age Verification Hub   eff.org/press/releases/ef... · Posted by u/iamnothere
MatteoFrigo · 2 months ago
This post is restricted to the context of the European Union and is intended to be factual.

The EU age verification app is intended to be a pilot to the EU Digital Identity Wallet (EUDIW), which EU law requires to be deployed everywhere in Europe by the end of 2026. (Thus your "worry" is in fact the explicit plan of record.)

The EUDIW will store more attributes than age. Think of it as a digital form of a passport (with name, address, etc.). The exact set of attributes is determined by local laws.

Thus, the DOCUMENT that you obtain is tied to you, and of course the state knows what is in the DOCUMENT since the state creates the document in the first place.

The state does not generate proofs. The phone generates proofs. Given a proof (and only the proof), nobody can associate the proof to the phone or to you.

Now I switch to less factual statements, which are still approximately correct.

Why would you trust the wallet software not to phone home to the state or us (Google)? The EUDIW regulations require that the wallet software be open source. However, states will only issue DOCUMENT to their own certified wallet software---you cannot just take the open source and recompile it, since the state won't issue DOCUMENT to your uncertified wallet. (Maybe your gym will issue a gym membership to your raspberry pi wallet, since it's not a big deal.)

The reason for this strictness is that the EUDIW is intended for official or semi-official uses. For example, you can open a bank account with it, or use it as ID to get a mortgage. The bank must by law accept DOCUMENT, the state guarantees that DOCUMENT is correct, and you get better privacy than handling over a piece of plastic that is then photocopied by who knows whom. This is the tradeoff of the current EU law. It would be inappropriate for this kind of official, passport-like documents to store attributes such as your profession (journalist or whatever), and nobody is talking about it.

donmcronald · 2 months ago
Thanks for replying to me. I'm having a tough time understanding how it's zero knowledge, but also tied to a person's identity. At some point I'm going to try to read the manuscript you linked to someone else, but I started skimming it and I'll be lucky if I understand a tiny fraction of it.

> The state does not generate proofs. The phone generates proofs. Given a proof (and only the proof), nobody can associate the proof to the phone or to you.

I get that part. I visit a website and it basically asks me to prove my DOCUMENT has an attestation for age and my phone generates the proof. The part I don't get yet is how it proves the issuer.

> However, states will only issue DOCUMENT to their own certified wallet software---you cannot just take the open source and recompile it, since the state won't issue DOCUMENT to your uncertified wallet.

I don't get why that would matter. I think of it in terms of proving you have a signed DOCUMENT (like a signed executable), but that concept doesn't work for a proof with a subset of data in the DOCUMENT. The wallet can't be trusted either, can it? What would stop me from running a proxy to tamper with the responses?

> Why would you trust the wallet software not to phone home to the state or us (Google)?

To be honest, I don't and I think calling certified wallets "tamper proof" is incorrect. They're tamper proof from the perspective of the users, but the designers, maintainers, policy makers can "tamper" at will.

> For example, you can open a bank account with it, or use it as ID to get a mortgage.

This starts to get into the biggest issue for me. As an average person, all I know is that I have this DOCUMENT with all my vital personal information on it and some of that information can be sent to a 3rd party that asks for it. Because it's such a complex technical system I have no way of understanding what's happening or verifying I'm only sending the information I expect them to be asking for. If it's a permission system like we have on phones, that's broken. People have been conditioned to think they need to click yes on everything or things won't work. I'd worry that suddenly people will be giving away vital information without even knowing.

> you get better privacy than handling over a piece of plastic that is then photocopied by who knows whom

On a technical level, that's right. On the level of an average person understanding what information they're handing over and how it's being used (or potentially misused), that's wrong. I understand perfectly what I'm handing over when I give someone my credit card or drivers license. A digital ID system is basically opaque to me.

We have to put 100% faith in a few companies; Google, Apple, etc.. We need to trust they're acting in good faith and getting the implementation perfect. The saying is trust but verify, but what happens when the system is so complex that not enough people can verify it does what it says, or, more importantly, that policy makers aren't giving classified orders that force the handful of certified wallets to change the way things work?

The technology is very cool. When I see documents like that manuscript you linked I'm envious. I wish I could understand the math well enough to conceptualize the whole system. I think there's a ton of value in leveraging technology to modernize identity. I also have no doubt the people working on the implementation are acting in good faith. Flat out though, I don't trust the institutions. There's always someone willing to act in bad faith for one reason or another.

I think it's important to understand there's a difference between analog verification systems and digital verification systems. If someone is checking my ID or comparing my face to pictures in a book of banned patrons, that has a natural limit on the scalability. Once things are digital, all bets are off. Think of the difference between a manager banning someone from a single store vs facial recognition being used to ban someone from every store in a chain. Digital IDs could very well be the next step up where people can be banned from participating in society.

Also think about the difference between fingerprint unlock for releasing a digital ID vs Face ID. With a fingerprint, you're creating a limit on what people will tolerate in terms of the number of times their ID is queried. With Face ID, people will tolerate a much larger volume. If the biometric ID is cached and allows multiple uses of a digital ID within X minutes, the number goes even higher. With a watch that's unlocked until you take it off your wrist, it's unlimited.

So, if you're working on these systems, consider there's more than just an algorithm and the implementation can leverage what the average person will tolerate to act as a bit of a check on the system. The fingerprint unlocking above is a good example where 1 fingerprint scan = 1 proof. People can understand that. Please don't build a system that allows for continuous identification.

Thanks for trying to explain some of the goals and how the system actually works. It's really hard to separate the politics from the technology, because they can't be separated, but I find it helps to have a better understanding of the technology as it helps when trying to focus on pragmatic concerns.

donmcronald commented on EFF launches Age Verification Hub   eff.org/press/releases/ef... · Posted by u/iamnothere
MatteoFrigo · 2 months ago
Excellent question. More generally, what prevents me from copying the credential and giving it to somebody else?

The currently favored approach works like this. The DOCUMENT contains a device public key DPK. The corresponding secret key is stored in some secure hardware on the phone, designed so that I (or malware or whatever) cannot extract the secret key from the secure hardware. Think of it as a yubikey or something, but embedded in the phone. Every presentation flow will demand that the secure element produce a signature of a random challenge from the RP under the secret key of the secure hardware. In the ZKP presentation, the ZKP prover produces a proof that this signature verifies correctly, without disclosing the secret key of the secure hardware.

In your example, the parent could give the phone to the kid. However, in current incarnations, the secure hardware refuses to generate a signature unless unlocked by some kind of biometric identification, e.g. fingerprint. The fingerprint never leaves the secure hardware.

How does the issuer (e.g. the republic of France) know that DOCUMENT is bound to a given fingerprint? This is still under discussion, but as a first bid, a French citizen goes to city hall with his phone and obtains DOCUMENT after producing a fingerprint on the citizen's phone (as opposed to a device belonging to the republic of France). You can imagine other mechanisms based on physical tokens (yubikeys or embedded chips in credit cards, or whatever). Other proposals involve taking pictures compared against a picture stored in DOCUMENT. As always, one needs to be clear about the threat model.

In all these proposals the biometric identification unlocks the secure hardware into signing a nonce. The biometrics themselves are not part of the proof and are not sent to the relying party or to the issuer.

donmcronald · 2 months ago
> How does the issuer (e.g. the republic of France) know that DOCUMENT is bound to a given fingerprint? This is still under discussion, but as a first bid, a French citizen goes to city hall with his phone and obtains DOCUMENT after producing a fingerprint on the citizen's phone (as opposed to a device belonging to the republic of France).

Are you saying that someone goes to city hall, shows ID, and gets a DOCUMENT that certifies age, but doesn't link back to the person's identity? And it's married to a fingerprint in front of the person checking ID?

Is there a limit on how many times someone can get a DOCUMENT? If not, it'll become a new variation of fake id and eventually there's going to be an effort to crack down on misuse. If yes, what happens if I get unlucky and lose / break my phone limit + 1 times? Do I get locked out of the world? The only way I can imagine limiting abuse and collateral damage at the same time is to link an identity to a DOCUMENT somehow which makes the whole ZKP thing moot.

I'd be more worried about the politics though. There's no way any government on the planet is going to keep a system like that limited to simple age verification. Eventually there's going to be enough pretense to expand the system and block "non-compliant" sites. Why not use the same DOCUMENT to prove age to buy beer? Sanity for guns? Loyalty for food?

What happens if the proof gets flipped to run the other direction and a DOCUMENT is needed to prove you're a certified journalist? Any sources without certification can be blocked and the ZKP aspect doesn't matter at that point because getting the DOCUMENT will be risky if you're a dissenter. Maybe there's an interview. Maybe there's a background check. Has your phone ever shown up near a protest?

It's just like the Android announcement that developers need to identify themselves to distribute apps, even via side loading. The ultimate goal is to force anyone publishing content to identify themselves because then it's possible to use the government and legal system to crush dissenting views.

Big tech caused most of the problems and now they're going to provide the solution with more technology, more cost, and less freedom which is basically what they've been doing for the last 2 decades so it's not a surprise.

u/donmcronald

KarmaCake day7607June 30, 2011
About
[ my public key: https://keybase.io/donmcronald; my proof: https://keybase.io/donmcronald/sigs/nJ3Can7EUoZLuDTXpPy5_132UQwdKyG7q4trVjvjFEw ]
View Original