> would not respect the privacy of the people
How does age verification break privacy? I have to show ID to get into an adult "bookstore," to enter a bar, or purchase alcohol. I have to show ID to check into my hotel, get through airport security, drive my car, buy Pseudo. Are you saying there is absolutely no way to perform this action online in a way that respects privacy just the same as all of those operations? No way at all to do a verification that's immediately tossed in a privacy preserving way?
If so, then it sounds like maybe things that require age verification shouldn't be allowed to operate on the internet.
There are cryptographic tools (zero-knowledge proofs, for example) that can provide anonymous attestations for a user's age. The problem is that the infrastructure to support it isn't provided by the same government that's requiring it to exist.
And even if the private sector innovated here, there's no approval from the government to accept math nerd solutions as legally valid.
Which means you basically have to scan and upload your photo ID to these websites, or use a payment card, or something else that will stand up in court.
Which makes sense, and also sounds like applying monetary pressure, say losing access to multiple states in the US, would incentivize prioritizing some engineers into solving this. The reason it doesn't exist yet, is because we've collectively decided through indifference and inaction that an "I swear bro" button is fine in the virtual world, but not the physical, and have now learned that it's not enough.
there is a HUGE difference between presenting ID in the physical world and digital world. In the digital world, once I provide an ID it is there forever. and it will be used for who knows what by who knows who. the only way to compare the two would be if in the physical world we provided an ID and whoever requested it gets to keep it and of course no place like that exists, you flash the ID (not that much unlike “I am 18 I swear” button in a lot of places) and you move on
Not that I think this is acceptable, but grocery stores around me scan your ID for alcohol purchases. In some states this is legally required.
At least with all the porn bills I've read, it's illegal to retain the information.
You didn't read the post you were replying to. That would be a "math nerd solution" that the states have not committed to accept, regardless of whether it actually works. Also, that sort of thing tends to require active cooperation from the entity issuing the IDs, which no state governments have committed to provide.
By the way, Pornhub actually has a preferred technical solution involving "device attestation". It's only marginally better than the snake oil the AV industry wants to use, and I don't like it, but they have said they'd stop objecting if something along those lines were standardized.
They just don't want to have to deal with a patchwork of mutually incompatible stuff (a) that's totally ineffective, (b) that leaves them either handling everybody's ID or dealing with questionable contractors to hold it, and/or (c) that leaves them having to convince the users to trust them or those questionable contractors with those ID images.
The commercial incentives around this are also terrible, given that the prevailing assumption is that a private third party will do the attestation as a for-profit service. It's practically guaranteed to add cost and liability for the porn vendor as well as risk of leaks, tracking, and data brokering for the consumer. It may as well have been designed to shut down free porn altogether.
And maybe it was, considering the history of porn regulation in the US. If you look at the requirements and contemporary rhetoric around 18 USC 2257 (yes, the thing that basically all legit porn sites with US operations have a disclaimer for), it was pretty blatantly intended to render the porn industry unable to operate. Porn producers were never actually intended to come into compliance, but rather presumed to be unable to (due to the ridiculous procedures and the supposed omnipresent use of underage, undocumented, and coerced performers).
> It may as well have been designed to shut down free porn altogether.
There was and is a fairly coordinated program of shopping this around to various legislative bodies (not only US states). It started maybe two years ago, I think. It didn't just catch on organically.
Some of it seems to be driven/funded by the AV companies, who presumably actually want the verification to happen. But a lot of the legwork and political contacts are provided by organizations that would definitely love to drive every porn site out of business. I doubt they expect to get all of them, or even all the free ones, but, sure, somebody like NCOSE knows that it's a major burden, and absolutely thinks that any damage to adults' access to porn is a positive feature.
It's not obvious that most of the legislators who vote for these things understand the implications at all.
So some of the people you could blame for this legislation definitely have such intentions, but probably not all of them.
> If you look at the requirements and contemporary rhetoric around 18 USC 2257 (yes, the thing that basically all legit porn sites with US operations have a disclaimer for), it was pretty blatantly intended to render the porn industry unable to operate.
Hmm. I'm ready to believe you, but 2257 doesn't seem totally infeasible to comply with in a VHS world. Dangerous to the performers, yes, because it requires tons of people to keep records of who they are and where they live, and those records are pretty much guaranteed to leak and be abused. An expensive nuisance, also yes. A chance to hound anybody who messes up out of business, and threaten them with prison, OK. Obnoxious overreach, sure. But totally impossible to comply with? I'm not sure about that. It actually seems easier than user AV.
The thing that always really got me about 2257 was that the claim was it was supposed to prevent another Traci Lords. They checked Traci Lords' ID. She showed ID. She had a real driver's license (based on a fake birth certificate, but it was the state that was supposed to check that, and anyway it was presumably a good fake). As far as I know, 2257 wouldn't even have slowed Traci Lords down.
Do these cryptographic tools prevent the government entity providing them from knowing which websites verify your age? If not, then that's too much Uncle Sam watching over your shoulder as you watch your porn.
Yes, they do precisely that, and in a way that depends only in math and cryptography. No possibility of leaking some naughty list after a hack.
It depends on the tool.
https://zkdocs.com https://zkdocs.com has some protocols described, if you're curious to learn more about this space.
> Are you saying there is absolutely no way to perform this action online in a way that respects privacy just the same as all of those operations? No way at all to do a verification that's immediately tossed in a privacy preserving way?
There's ways yes but the bigger issue is that it's much harder to verify. When I show my ID to a cashier I can see whether they photocopy it or not. I can't verify websites and porn ones could be shady.
Not that I personally care that people know I watch porn. But maybe people do care.
> No way at all to do a verification that's immediately tossed in a privacy preserving way?
Not if you want to be able to pass any kind of audit, no. Not unless the authority issuing the ID participates in a complicated cryptographic protocol. Which none of them do and which is definitely not standardized.
One of the early states passing these, I think it was Louisiana, actually did at least try to step up and deal with the privacy issue. They came up with a trusted-third-party thing. The third parties, who are private entities, have to pinky promise not to leak the data or keep them beyond certain limits. They are not audited. There are no actual penalties if they screw up. That's not acceptable assurance. There are also no limits on what they can charge, come to think of it, and it's not exactly going to be a large fluid market.
None of the other states even went that far. Nor did any of them try to come up with a shared standard.
There's definitely nothing out there that the user can verify as working, or that's certified by anybody the user should trust.
There are also the facts that--
1. All of the "age verification" protocols that the various activists are pushing and the various vendors are hawking are ineffective, in that any halfway motivated kid can easily figure out how to circumvent them, and
2. Kids just seeing porn isn't actually a big problem, especially if they've sought it out.
It makes complete sense to resist this BS.
I've seen no auditing requirements on any bill, and in fact all that I've read make it illegal to retain information used for verification. Audits also aren't done in person; stings are. Why does auditing always come up with this topic?
It seems to me that these bills aren't prescriptive (they say you can use a "commercially reasonable" method). Most states are also moving to adopt the ISO mDL standard[0].
[0] https://www.mdlconnection.com/implementation-tracker-map/ https://www.mdlconnection.com/implementation-tracker-map/
> Audits also aren't done in person; stings are.
What? First, that has nothing to do with anything. Second, it's not true: most auditing has an in-person component, and many stings don't. Do you actually know what an audit is? Hint: a "pen test" isn't an audit and isn't much like an audit. Neither is a code review.
> Why does auditing always come up with this topic?
1. All security controls need to be audited.
2. There is a 100 percent chance that many of the organizations advocating for these laws, most of which would actually prefer for porn to be outlawed completely, will grab any chance they can to accuse sites of not complying. They'll either try to get sympathetic law enforcement agencies to take up those accusations, or, if they can find a legal avenue, they'll bring lawsuits themselves. They will undoubtedly find anecdotes of system failures, since any large-scale system will fail sometimes. They will claim that as evidence that the rules aren't being followed. Evidence, no matter how flimsy, has to be countered with other evidence, especially if you're in a "preponderance of the evidence" situation. It's pretty hard to show that what you're doing is reasonable or effective if you don't have at least a sample of records.
I actually don’t think there’s a way to “toss” that information, no. In fact, if you don’t use any content blockers, and never clean your cookies - chances are the browser fingerprints and databasss already know your age with 90% certainty. Without any pictures of your documents flying around.
Most if not all of those were met with complaints that we were on the slippery slope towards being a police state where the government forced its way into private matters.
Given that, your argument seems to be that since we are on the slippery slope, we might as well go further.
For what it's worth, I don't have to show ID to get into an adult bookstore, or enter a bar, or purchase alcohol, because I live in a place which doesn't require ids for people who are obviously old enough.
I've also stopped flying in part because I think airport security is oppressive and a facade, and I don't drive because I managed to find a place where I'm not forced to have a car to live. I hate the pseudoephedrine id law because I think the state should have no business in that matter, and like airport security it's a case of the government seeming to Doing Something even though it does nothing.
Last time I needed pseudoephedrine, I got a friend to buy it for me.
> Are you saying there is absolutely no way to perform this action online in a way that respects privacy just the same as all of those operations?
Correct. I can buy wine without an id because the store clerk can physically verify that I am of age without checking a piece of plastic or otherwise establishing my identity.
Once purchased I could of course give it to a local 16 year old, which would be illegal, but an id check wouldn't change things.
You'll have to have a camera check the user before each porn site visit, or at random checks, and deal with the false positives of a 16-year-old which looks 19 (or false negatives of a 21 year old who looks 17), and strict laws preventing any recording of that information, and somehow assure people that the laws will never change to collect more information - which is hard to believe given the slippery slope shown at airports and elsewhere.
> maybe things that require age verification shouldn't be allowed to operate on the internet.
How do you propose we do that? Block off all IP addresses at the national level for porn site servers hosted in other countries? Block DNS lookups for them? Prevent VPN use? Nix their ability to charge via Visa and MasterCard, or take payments via SWIFT?
One thing is to have someone visually checking on your ID you're an adult, another thing is to record your full name and IP address, along with the site you access, who knows on what insecure database and probably forever. When you leave a brick-and-mortar adult store, no one asks you what your name is, records it down next to your purchase, and sends it to state authorities.
These are two very different things.
This law is not only about Pornhub or porn, but about anything each state government consider "harmful". Porn is the excuse for blocking you from accessing, in a not-so-distant future, any topic your local government frames as harmful.