Re: A less-circumventable age verification protocol: good ol' files

Lucas Holt <[email protected]> Thu, 12 Mar 2026 17:22:13 -0400
Newsgroups gmane.linux.xdg.devel
Message-ID <[email protected]>
On 3/11/26 7:26 PM, Thiago Macieira wrote:
> Opening files isn't proof either, as one can LD_PRELOAD a stub library that
> intercepts opening of certain files and redirects to opening something else.
> And if the whole issue is to provide information to websites, one can patch
> the browser and recompile, to provide whatever information is desired.
>
> To solve all of this, one needs a cryptographically-signed blurb to be
> provided to said websites, which they can then verify authenticity of.
> Moreover, it needs to be resistant to replay attacks, so in turn it must be an
> API that signs with a challenge provided by the website in the first place.
>
> This gets technically difficult very quickly. I'd argue it's well past
> reasonableness.
To clarify, it's not just websites.  App stores aka package repos are 
also impacted. Browsers are one part of this but not the only part.  
This is true for NY, CA, IL and CO bills.

Lucas Holt
[email protected]
________________________________________________________
MidnightBSD.org (Free OS)
JustJournal.com (Free blogging)