this post was submitted on 01 May 2026
115 points (98.3% liked)
Canada
11924 readers
470 users here now
What's going on Canada?
Related Communities
🍁 Meta
🗺️ Provinces / Territories
- Alberta
- British Columbia
- Manitoba
- New Brunswick
- Newfoundland and Labrador
- Northwest Territories
- Nova Scotia
- Nunavut
- Ontario
- Prince Edward Island
- Quebec
- Saskatchewan
- Yukon
🏙️ Cities / Local Communities
- Anmore (BC)
- Burnaby (BC)
- Calgary (AB)
- Comox Valley (BC)
- Edmonton (AB)
- East Gwillimbury (ON)
- Greater Sudbury (ON)
- Guelph (ON)
- Halifax (NS)
- Hamilton (ON)
- Kingston (ON)
- Kootenays (BC)
- London (ON)
- Mississauga (ON)
- Montreal (QC)
- Nanaimo (BC)
- Niagara Falls (ON)
- Niagara-on-the-Lake (ON)
- Oceanside (BC)
- Ottawa (ON)
- Port Alberni (BC)
- Regina (SK)
- Sarnia (ON)
- Saskatoon (SK)
- Squamish (BC)
- Thunder Bay (ON)
- Toronto (ON)
- Vancouver (BC)
- Vancouver Island (BC)
- Victoria (BC)
- Waterloo (ON)
- Whistler (BC)
- Windsor (ON)
- Winnipeg (MB)
Sorted alphabetically by city name.
🏒 Sports
Baseball
Basketball
Curling
Hockey
- Main: c/Hockey
- Calgary Flames
- Edmonton Oilers
- Montréal Canadiens
- Ottawa Senators
- Toronto Maple Leafs
- Vancouver Canucks
- Winnipeg Jets
Soccer
- Main: /c/CanadaSoccer
- Toronto FC
💻 Schools / Universities
- BC | UBC (U of British Columbia)
- BC | SFU (Simon Fraser U)
- BC | VIU (Vancouver Island U)
- BC | TWU (Trinity Western U)
- ON | UofT (U of Toronto)
- ON | UWO (U of Western Ontario)
- ON | UWaterloo (U of Waterloo)
- ON | UofG (U of Guelph)
- ON | OTU (Ontario Tech U)
- QC | McGill (McGill U)
Sorted by province, then by total full-time enrolment.
💵 Finance, Shopping, Sales
- Personal Finance Canada
- Buy Canadian
- BAPCSalesCanada
- Canadian Investor
- Canadian Skincare
- Churning Canada
- Quebec Finance
- Canada Grown Business
🗣️ Politics
- General:
- Federal Parties (alphabetical):
- By Province (alphabetical):
🍁 Social / Culture
- 2 North American 4 You (Shitposting & Memes, North America focus)
- Ask a Canadian
- Bières Québec
- Canada Francais
- Canadian Gaming
- Eh Buddy Hoser (Shitposting & Memes, Canada focus)
- EhVideos (Canadian video media)
- First Nations
- First Nations Languages
- Indigenous
- Inuit
- Logiciels libres au Québec
- Maple Music (music)
Rules
- Keep the original title when submitting an article. You can put your own commentary in the body of the post or in the comment section.
Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage: lemmy.ca
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Age verification would be fine if it was an OAuth type thing - I sign in with the government on the government's website, they report back that I have the 18+ grant. I don't know why they're going in this direction of just requiring that private companies collect a bunch of personal information to "verify" me
Is there anything to stop the government side from compiling a list of users and the sites that request verification? Because that just makes a centralized target for hacking or internal crime. There's got to be a way that allows for both verification and zero trust :/
I mean...yeah...but it sounds really bad on the surface.
Crypto. Namely, certificates or smartcards.
Imagine if your driver's license were a smartcard. It'd essentially just be a cryptographic key pair that asserts that you are "you" because the card says you are and you both have the card and know the unlock PIN.
Now, that sounds like the government could easily track you, but not quite. All that really matters is that the certificate is valid. Not expired, not revoked, and there is a mutual trust in a third party (the issuer).
This doesn't require a query to the issuer. It can, and should, i.e. using OCSP or CRLs. CRLs, in particular, are a bit better here...instead of the service going back to the issuer and saying "is this certificate still good", instead, the issuer periodically publishes a list of all revoked serial numbers that get downloaded by anybody who wants them.
The important thing is, the service provider (i.e. the website) never has to ask about you by name. They know you are you, because you possess your private keys, and they trust that the issuer of your certificate (a corresponding public key, signed by the issuers private key) is thorough in verifying your identity.
I think a mutual-third-party trust model (basically, certificates) is about as good as it can get. I don't think you can verify without trust. That's not how the proverb goes. Not at all.
This is the way. There are many cryptographic ways to make this possible without sharing any personal or usage information with any party. Too bad our legislators as a group are too fucking stupid to understand any tech more complicated than two cans with a string.
Such is the problem. IME, most people in tech can't wrap their heads around PKI, I have zero faith in legislatures to do so.