• 0 Posts
  • 11 Comments
Joined 6 days ago
cake
Cake day: August 28th, 2025

help-circle


  • specifically this is how QUANTUMINSERT worked (from the Snowden leaks.) also China used the same technique, injecting malicious JS through the GFW to get bystanders to DDoS github, in a much more obvious and indiscriminate way.

    nobody here is remotely likely to be targeted by NSA, of course, but you can actually do such attacks on a budget if you compromise any router in the chain. combined with a BGP hijack it’s not far out of reach for even a ransomware gang to pull something like that these days.



  • this is sounding sketchier and sketchier. so every website that serves 18+ content in Denmark will need to check tokens against a central database upon login? forget censorship and surveillance, that sounds like it plain won’t scale well. also does Denmark really expect every website to implement this? what about Lemmy or other fediverse services?

    why is this needed at all? why not just use parental controls on devices? why is this such a crisis now, for the first time in 20 years?

    I feel like they could just, you know, not do this.





  • what prevents you from leaking your token on the internet, so everyone can use it? it has to be revokable somehow. to be revokable it has to be correlatable, so you can tell where the same token is used across multiple sites. which leads to easy deanonymization.

    ZKP is window-dressing. it’s still a major privacy intrusion. don’t fall for it.

    (also, it paves the way for lgbt issues, sex ed, harm reduction and activism to be censored behind the 18+ barrier, but that’s a different matter.)