logoalt Hacker News

baby_souffletoday at 12:28 AM1 replyview on HN

> How? Phones are already locked down pretty hard

But never well enough, it seems.

If you can't revoke the token then I'll just sell mine to whomever needs it.

Kids will beg/borrow/steal their parents / older siblings ... etc.

The "harden the device, bake in controls that are difficult to circumvent and managed by not-the-primary-device-user" approach is _very_ similar to DRM. All that does is punish the innocent.

I have never once had VLC tell me that the mkv file I just opened can't be played because I'm not in the right region or because my screen is too old to support encryption. I have had family learn the hard way that DRM is not in their best interest, though. Now they just ask me for the movie on a pen drive when I visit next :).


Replies

ben_wtoday at 6:57 AM

> But never well enough, it seems.

"Never well enough" for stopping teens (and pre-teens) installing access tokens?

Has any adolescent in history ever managed to so much as spoof someone else's session cookie *on their phone*? And if so, when? If this is a flaw which comes up once every five iOS versions or whatever, who cares?

> Kids will beg/borrow/steal their parents / older siblings ... etc.

They occasionally get alcohol, too, despite restrictions. The point is to *mostly* stop them.

And it's not like the payment systems have not already solved the same problem.

> All that does is punish the innocent.

Which is literally something I'm trying to solve with my suggestion up-thread: here's a way to do age attestation that doesn't need to punish anyone.