4 ms·
Far better to promote device controls than service ID checks. * It allows parents to decide what age to allow kiddo to see certain content, not the state. * I
by advisedwang 1y ago
Far better to promote device controls than service ID checks.
* It allows parents to decide what age to allow kiddo to see certain content, not the state.
* It allows others to restrict content too. E.g. a gambling addict who doesn't want to see gambling content.
* It has no risk of leaks etc for adults.
I'd like to see laws mandating that service provides respect a new content restriction header or something like that.
- trinix912 1y agoBut wouldn’t that be too easy to counterfeit? Or if it were handled by a special government-approved piece of software that’s then just DRM all over again.
- stebalien 1y agoCounterfeit what? This is about labeling and filtering: the device doesn't present an ID, the device prevents the user from accessing content with/without specific labels if so configured. Specifically, governments mandate that: 1. Websites/apps/etc. MAY label content (via headers) indicating when their content/service is/isn't appropriate for some specific audience (e.g., children) according to X/Y/Z regulations. Websites/apps/etc. MUST NOT incorrectly label their content. 2. Devices that can access the internet must not be sold directly to miners without parental consent. 3. Devices that can access the internet must include parental control software can be configured to allow/forbid all apps/content that may contain content not deemed suitable for children (in the jurisdiction where the device is sold). Importantly, this kind of solution solves the "borderless internet" problem: 1. Device sellers are regulated in the jurisdiction where they sell the device. 2. Service providers take no (additional) per-jusrisdiction responsibility until they start labeling their content. By labeling their content, they are claiming to abide by specific regulations.
- WarOnPrivacy 1y ago> governments mandate that ... Websites/apps/etc. MAY label content (via headers) indicating when their content/service is/isn't appropriate Which government? This list of pornographic film studios indicates they reside in many countries. https://en.wikipedia.org/wiki/List_of_pornographic_film_studios https://en.wikipedia.org/wiki/List_of_pornographic_film_stud... Past that, the USA alone has thousands of governments. Many have opinions.
- scott_w 1y agoUnfortunately the UK has demonstrated that it’s quite possible to go after a lot of adult material even beyond our borders.
- stebalien 1y agoI completely agree. I'm not saying that all websites containing nudity must contain a "nudity" label as defined by some specific country, I'm saying: 1. Governments MAY define labels like "gov.texas.bill1234-compliant". 2. Websites MUST NOT apply this label to their content unless the content actually complies with Texas' bill1234. Websites may ALSO proactively label their content with advisory labels like "advisory.may-contain-nudity", but those would have no legal meaning.
- WarOnPrivacy 1y ago> I'm saying ... Governments MAY define labels like "gov.texas.bill1234-compliant". What do we think a Latvian porn host is likely to do in response to that?
- ndriscoll 1y ago> 3. Devices that can access the internet must include parental control software can be configured to allow/forbid all apps/content that may contain content not deemed suitable for children (in the jurisdiction where the device is sold). Highly likely to be the end of free software/general purpose computing, which would be quite a bit worse than identifying yourself to companies providing adult material (in a world where ads haven't corrupted everything, you'd identify yourself when paying for it anyway just like any other e-commerce transaction).
- stebalien 1y agoI'm saying that devices must be sold with this parental control software, not that this software must be used/activated. Most devices already have support for restricted modes like "guest mode".
- phatskat 1y agoI think the “must” is probably a bit much, however we could have something similar to Energy Star but call it something like “Child Star” (I mean, POTUS would back it). If you want to be Child Star certified, you need to provide access controls that conform to whatever standard web hosts implement. Parents could be encouraged to buy such products, and this would market well to the parents who complain about what their kids watch on YouTube but also can’t be bothered to _parent_ and actually curate said content. I think age verification is a losing battle that does what most similar schemes do: make it harder for legitimate users while not having a large impact on the purported problem. All while providing another way to track user data and create huge privacy risk. I’m all for some kind of opt-in or certification system that allows websites that care and parents who care _enough_ to work together to address whatever problem they perceive while letting the rest of us go about our business not even noticing a change in the online landscape.
- chmod775 1y agoThis might somewhat reliably work for children aged up to ~8, but above that many determined literate children will be able to circumvent these things for themselves and their friends. We had all kinds of tricks up our sleeves to play RuneScape in CS class and read various video game guides that would have normally been blocked by word filters in the school's proxy server. How are you going to stop a kid who figured out how to boot some Linux from portable media and is now handing these out to their entire friend group? At some point your only option is to closely watch them every second, but then what's the point of all that electronic parental control nonsense in the first place? The only reason these kinds of controls may appear to work is that younger children simply aren't interested in the stuff that may be blocked.
- stebalien 1y agoYeah, I agree. Nothing will stop a determined and smart child from getting what they want. My goal is to describe a system that's as secure as ID verification without all the drawbacks.
- neruthes 1y agoI think the current boot feature will disallow arbitrary EFI booting. And most mobile device manufacturers do not allow bootloader unlocking for consumers. That being said, there is no guarantee that a determined child will be prevented from apt install git build-essentials and cloning Chromium source code and compile a modified version of Chromium; or from using ncurses and libcurl to hand-make their own tiny browser; or from receiving a premade browser using nc -l 8080 > www.AppImage. As long as the exposed functionalities are Turing-complete and any tiny networking is possible, a determine child will eventually make it happen.
- mindslight 1y ago"Give websites your ID" requires doxing yourself to every site out there, including forums etc which will heartily embrace the excuse to dox you. "Magic ZKP faerie dust" still requires locked down corporate controlled devices implementing remote attestation that destroys everyones ability to run the code of their choosing on their device (see UK's system). Of course Google advertises the cool seems-like-privacy ZKP part rather than the totalitarian remote attestation/"Safety"Net/WEI part. Filters on the device, including preventing kids booting/installing alternative software only requires devices to prevent easily running other OS images on demand. Boot signatures suffice. And if designed to support it, filters could also be run on the router or by a mobile provider. That last approach is still the least freedom-destroying, by far.
- seanalltogether 1y agoI completely agree. Android devices already have rudimentary access controls for kids through Family Link. I'd much prefer governments put pressure on Google, Apple and Microsoft to provide full control of locking down devices, apps and websites that can be managed through a kind of family service. Let me lock things down using government supplied blocklists, or google, apple blocklists with the ability to selectively enable whatever i want for the kids.
- 0x000xca0xfe 1y agoSame approach could have prevented the cookie banner disaster: Simply require websites by law to respect user settings. Like the DNT header or an "Underage: yes" header and almost all such problems would not even exist. But obviously this is not what governments really want. They want control. They want to see people self-censor. They want the panopticon.
- xinayder 1y agoFunny how a couple of years ago, big tech was against age verification, claiming they were "defending" privacy rights. Fast forward to now, it doesn't seem a bad idea for them.
- raxxorraxor 1y agoBecause they found a way to profit from this data as well and the most stupid users just accept giving away their id. Parents also don't care if their kid is sitting 5h daily in front of some roblox gambling machine.