The World Cup ticketing mess is an identity problem, not a supply problem

If you spent hours in a online queue for World Cup tickets just to see them pop up on resale sites for a massive markup, you know how broken the system feels. But this is no longer just a regular bot problem. It is a fundamental design flaw. Ticketing platforms are trying to fight modern AI using security tools built for an older version of the internet.

The AI Advantage:

Old-school bots were easy to spot because they clicked too fast or acted like machines. A simple CAPTCHA puzzle could usually stop them.

Today, scalpers use smart AI frameworks like World’s AgentKit. These AI agents can look at a screen, solve puzzles on their own, and purposefully mimic human behavior, like adding natural pauses or moving the mouse unevenly. Because they act exactly like a real person, standard security software cannot tell the difference between an AI agent and an actual fan.

The Surveillance Trap

Because platforms cannot catch the AI, their backup plan is to demand absolute tracking. They are forcing fans to upload passports, government IDs, and live facial scans just to buy a ticket.

This creates a massive security risk. You are handing over your permanent biometric data to central corporate databases built for a short-term event. These systems are prime targets for hackers. If they leak, a bad actor does not just get a credit card number—they get your actual face and legal identity.

A Better Approach: Proof of Human

We do not need to give up our private documents to prove we are not software. The solution is switching from tracking who someone is to simply verifying what they are.

This is where decentralized proof-of-personhood tools, like World ID, come in. By using privacy-focused math, a ticketing system can check a simple fact: is this account tied to a unique, living human?

It verifies you are a real person without ever knowing your name, passport details, or location. More importantly, it enforces a strict limit of one ticket allotment per human. A scalper could still run thousands of AI agents, but without thousands of unique human signatures to back them up, the agents become completely useless.

Until the ticketing industry shifts toward privacy-first human verification, fans will keep losing out to automated networks.

reddit.com
u/Electrical_Mine1912 — 2 months ago

ML Engineers Using AI Agents in Production — What's Your Experience?

I've been experimenting with AI agents for a few internal workflows and the gap between demos and production has been larger than I expected.

The biggest challenges so far have been reliability, tool-calling failures, and evaluating whether an agent is actually improving outcomes versus adding complexity.

For those running agents in production:

  • What use cases have delivered real value?
  • Which frameworks are you using?
  • What broke that you didn't expect?
  • How are you evaluating performance and ROI?

Curious to hear both success stories and cautionary tales.

reddit.com
u/Electrical_Mine1912 — 2 months ago

Anyone else surprised 30 Seconds to Mars is actually touring again

Genuine question. I used to listen to 30 Seconds to Mars quite a bit back in the day and recently noticed they're still doing major live shows.

It got me wondering what fans and casual listeners think of them now compared to their earlier years.

If you've seen them live recently, was it worth it? How was the crowd, the production, and the overall atmosphere?

Curious to hear some firsthand experiences because I haven't really followed the band in a while.

reddit.com
u/Electrical_Mine1912 — 2 months ago

What's the general opinion on 30 Seconds to Mars these days?

I was randomly looking up some live music and realized 30 Seconds to Mars is still actively touring and playing shows.

It's kind of wild considering how long they've been around. I remember listening to The Kill, From Yesterday, and Kings and Queens years ago, and I honestly hadn't kept up with the band much since then.

For anyone who's seen them recently, how are the live shows these days? Do they still play a good mix of the older songs or is the set mostly newer material?

reddit.com
u/Electrical_Mine1912 — 2 months ago

Could proving uniqueness become more important than proving identity?

Most identity systems focus on answering the question: "Who are you?"

But for many online services, the more important question might be: "Are you a unique person?"

I'm curious whether others see uniqueness and identity as fundamentally different problems, especially from a privacy perspective.

reddit.com
u/Electrical_Mine1912 — 2 months ago

Is proving you're human fundamentally at odds with privacy?

It seems like many online services are moving toward stronger verification systems to deal with spam, fraud, and automated abuse.

At the same time, privacy advocates have spent years pushing for less data collection and fewer identity requirements.

Do you think it's possible to verify that someone is a real person without creating new privacy risks, or are these goals always going to be in tension with each other?

reddit.com
u/Electrical_Mine1912 — 2 months ago

Are privacy-preserving techniques actually being used in production ML systems? [D]

I've been reading more about privacy-preserving ML approaches such as differential privacy, federated learning, and on-device inference.

The research literature is fairly active, but I'm curious about real-world adoption.

For those working in industry:

  • Are these techniques being deployed in production?
  • What were the biggest engineering challenges?
  • Did privacy requirements significantly impact model performance or infrastructure costs?
  • Are there specific use cases where privacy-preserving approaches have proven especially valuable?

Interested in hearing both success stories and cases where the tradeoffs made adoption difficult.

reddit.com
u/Electrical_Mine1912 — 2 months ago

What was the first sign that made you realize your identity had been compromised?

I've been reading a lot about identity theft cases recently, and it seems like many people don't discover it immediately.

For those who have experienced identity theft or account takeover, what was the first warning sign?

Was it:

  • A strange login notification?
  • An unfamiliar credit inquiry?
  • A bank alert?
  • A password reset you didn't request?
  • Something else entirely?

I'm interested in learning which warning signs people wish they had recognized sooner and what steps they took after discovering the issue.

reddit.com
u/Electrical_Mine1912 — 2 months ago

Will digital identity eventually become a reputation score?

As more services become interconnected, it feels like our digital identities are increasingly tied to access, trust, and opportunities.

Between:

  • Verification systems
  • Professional profiles
  • Social signals
  • AI-generated risk assessments

Do you think we're moving toward a world where digital identity becomes a form of reputation score? What will be the privacy and security implications if that happens?

reddit.com
u/Electrical_Mine1912 — 2 months ago

Do developers think about privacy early enough in the development process?

As developers, it's easy to focus on features, performance, and deadlines.

Privacy considerations often seem to appear later in the process, usually when compliance requirements or user concerns arise.

For those involved in software development, how often is privacy considered during initial design decisions versus being addressed after implementation?

reddit.com
u/Electrical_Mine1912 — 2 months ago

Will proving you're human become a normal part of using the internet?

Spam, bot networks, automated account creation, and AI-generated content seem to be increasing across many online platforms.

I find myself wondering whether websites and online services will eventually require stronger ways of distinguishing humans from automated systems.

Do you think this is where the internet is heading, or are there better approaches that preserve privacy without introducing additional verification requirements?

reddit.com
u/Electrical_Mine1912 — 2 months ago

How much personal information is actually needed to impersonate someone online?

I've been thinking about how much information we voluntarily share across different platforms without realizing how it can be combined.

A name, email address, employment history, social profiles, and a few public posts may not seem sensitive individually, but together they can paint a surprisingly complete picture.

For those who work in security or privacy, what information do you consider most valuable to attackers when attempting impersonation or account takeover?

reddit.com
u/Electrical_Mine1912 — 3 months ago

Has identity theft become easier to scale in the age of AI?

A few years ago, identity theft seemed like something that required a lot more effort from attackers. Today, with AI tools capable of generating convincing emails, messages, and even voice content, it feels like the barrier to entry has become much lower.

I'm curious whether privacy professionals and security practitioners see this as a significant shift or simply an evolution of existing social engineering tactics.

Do you think AI has fundamentally changed the identity theft landscape, or is it mostly making old techniques more efficient?

reddit.com
u/Electrical_Mine1912 — 3 months ago

¿Cómo están manejando identidad y autenticación en aplicaciones con IA?

Últimamente he estado viendo más aplicaciones que integran asistentes de IA, agentes o automatizaciones que pueden realizar acciones en nombre de un usuario.

Algo que me genera curiosidad es cómo se está manejando la identidad en estos casos. Autenticar a un usuario es relativamente sencillo, pero cuando una aplicación empieza a tomar acciones automatizadas, la separación entre usuario, sistema y agente parece menos clara.

Para quienes trabajan en productos con componentes de IA, ¿ha cambiado algo en la forma en que diseñan autenticación, permisos o auditoría de acciones?

reddit.com
u/Electrical_Mine1912 — 3 months ago

What are the current limitations when evaluating LLM-based agents in real environments?

Most evaluation methods for LLM systems still seem heavily tied to benchmarks like coding tests or static QA datasets. Those are useful, but they don’t really reflect how these systems behave once you put them into more dynamic environments.

In real applications, agents are often using tools, making multi-step decisions, and working with context that changes over time. Failures in those situations also tend to be harder to reproduce or measure consistently.

I’m curious how people working closer to applied systems are thinking about this. Is there any direction toward more standardized evaluation for agent behavior, or is this still something that varies too much between implementations?

reddit.com
u/Electrical_Mine1912 — 3 months ago

Are we becoming too dependent on third-party services online?

It feels like more and more online services depend on third parties for analytics, authentication, advertising, cloud hosting, and user tracking.

While this makes development easier and often improves convenience, it also means user data frequently passes through multiple organizations that most people have never heard of.

I'm curious how people here think about this tradeoff. Are the privacy costs of this ecosystem properly understood, or have we simply accepted it as the default way the internet operates?

reddit.com
u/Electrical_Mine1912 — 3 months ago

What is the most underestimated cybersecurity risk right now?

A lot of attention goes toward ransomware, phishing, and major breaches, but I'm interested in the risks that don't get discussed as often.

In your experience, what threat do organizations consistently underestimate? It could be something technical, operational, or even related to human behavior. I'm interested in hearing about issues that rarely make headlines but create real problems in day-to-day security work.

reddit.com
u/Electrical_Mine1912 — 3 months ago

How are organizations preparing for AI-generated phishing attacks?

Over the last year, it seems like the barrier to creating convincing phishing emails has dropped significantly. Attackers no longer need strong writing skills or a good understanding of the target's language to produce believable messages at scale.

I'm curious how security teams are adapting to this shift. Traditional awareness training often focuses on spotting spelling mistakes, unusual wording, or obvious red flags, but those indicators seem less reliable now.

Are organizations changing how they approach employee training and phishing detection, or are existing defenses still proving effective?

I'm particularly interested in hearing from people who have seen measurable changes in phishing campaigns over the past year.

reddit.com
u/Electrical_Mine1912 — 3 months ago
▲ 0 r/merval

¿Creen que en el futuro vamos a necesitar verificar que somos humanos para usar servicios financieros online?

Con la cantidad de bots, cuentas falsas y herramientas de IA que aparecen cada día, me pregunto si dentro de algunos años la verificación de identidad va a cambiar bastante.

Hoy la mayoría de los bancos, brokers y fintechs usan KYC tradicional: DNI, selfie, comprobantes, etc.

Pero el problema que parece crecer más rápido no es "¿quién sos?" sino "¿sos una persona real?".

¿Ven posible que en el futuro existan sistemas que permitan demostrar que sos un humano único sin revelar datos personales cada vez que usás un servicio?

¿O creen que eso inevitablemente termina afectando la privacidad?

Me interesa especialmente la opinión de quienes trabajan en fintech, compliance o ciberseguridad.

reddit.com
u/Electrical_Mine1912 — 3 months ago