• 11 Posts
  • 849 Comments
Joined 3 years ago
cake
Cake day: June 11th, 2023

help-circle




  • no way to verify it isn’t beyond “trust me bro” and I don’t trust them

    If the verification service is structured like oauth, then the request could be passed through the browser as signed plaintext. You could verify that the requesting site is only passing a minimum age request to the service. That would be as straightforward as viewing the interaction in your browser’s debug tooling.

    If you say that you don’t trust the signature, and that it could be used to smuggle identifying information across, there’s a couple of ways to deal with that: open source and audited provider governed by legislation; information theory that would show personally identifying information wouldn’t fit into a field of that size; and “personal auditing” where you can try throwing data at the service to see if you can trick it into accepting invalid input (that really goes with the previous point, because the only field you can usefully vary is the signature).






  • sbv@sh.itjust.workstoSoftware Gore@lemmy.worldUhhh
    link
    fedilink
    English
    arrow-up
    33
    ·
    20 days ago

    Years ago I had to work with a Java library that had the same kind of cutesy errors. I think it was jxta. It was terrible. It would collapse if I looked at it funny.

    The first time I got an error like that, I thought how random and cute the devs were.

    The second, I thought they were just like me.

    The third, I was a little annoyed that they seemed to put more effort into their error messages than their software.

    The fourth, I was annoyed that i had to read past their drek to find the error.

    The fifth, I hated them.

    The sixth, I wanted to find and punch them.

    The seventh+, I swore I would never deal with their shit again if I could avoid it.