599
Stop Killing The Internet: No Digital ID & No Age Verification | European Citizens' Initiative
(citizens-initiative.europa.eu)
This is a most excellent place for technology news and articles.
Response to 1: funny thing is that one of the ID verification issues I specifically had is with Hetzner. They need to do a ID verification, recognizes my address is from Country A outside of the EU, so it goes through a Country A specific verification. Then rejects my ID because it's a rare form of ID in Country A. I also have an ID for Country B but they won't recognize it with a Country A address.
Response to 2: I'm specifically referring to people residing in the EU for this one. People in the EU that "slip through the gaps" since their ID is somewhat uncommon, thus getting locked out of digital services since they can't validate and obtain a digital ID easily.
Response to 3: the counterpoint here is network transport protocols, such as TCP and UDP. At this point, it is no longer possible to build new protocols or modify these protocols because of how entrenched the infrastructure hacks surrounding these protocols are, such that no new protocol header would be possible to get through the Internet without it being dropped by middleboxes. I'm suggesting utilizing this technical moat as a feature here: have a simple proposal spread so wide that it becomes almost impossible or economically unfeasible to switch to something invasive.
My issue with 4 is more about current implementation rather than the proposal. So far, the main (or only functional implementation, I'm not sure) is the one that depends on Google attestation. While this could change, I'm not the biggest fan of trusting something to "policy/proposals". X509 is robust, has key management sorted out, and doesn't have this specific issue. While anyone can create a cert, that doesn't mean the cert is useful if it's not signed by an approved CA.