3 ms·
You're doing the thing where you hold age-verified requests to an unreasonably high standard of privacy, ignoring the status quo. The absolute majority of porn
by sltkr 1y ago
You're doing the thing where you hold age-verified requests to an unreasonably high standard of privacy, ignoring the status quo.
The absolute majority of porn viewers access a mainstream site like Pornhub through their home or mobile ISP, which is required to verify the owners identity. So in practice, if you're an average user (note: Hacker News users aren't average users) your ISP already knows which porn sites you visit, and your privacy is dependent entirely on your ISP not sharing that information with the government or other organizations.
If you look closely you'll see that none of your concerns are actually valid.
> You do not want the government to know which websites you visit. This rules out any kind of redirect / forwarding via a government website or app.
Technically trivial (e.g. using Referer-Policy: origin).
> You do not want websites to correlate their requests
Impossible to guarantee today.
Yes, this sucks, but this is not a failure of age verification.
> You do not want a website to correlate multiple data requests
This isn't the norm today. For example, Pornhub today already doesn't work without cookies. That doesn't stop users from flocking to it.
Still, it _would_ be technically possible to provide this; see Cloudflare Turnstile for an example. But nobody cares; neither mainstream users nor site owners want stateless websites.
> as that would allow websites to create some kind of supercookie.
No it wouldn't.
> You want the request to be unique and time-bound. It should not be possible to replay a response, either to the same website or a different one.
Technically trivial.
> You do not want to send more data than strictly necessary. If a website needs to know if you are 18 or older, it should only receive a boolean flag.
Technically trivial.
So to summarize: literally all of your concerns are easily dismissed as either easily solvable or already part of how the web works. None of it is pertinent to the topic of age verification.
- Seattle3503 1y ago> You're doing the thing where you hold age-verified requests to an unreasonably high standard of privacy, ignoring the status quo. There is a lot of this going on in this thread and frankly it is quite frustrating. Texas and France are two jurisdictions I know implemented privacy laws and now porn websites are collecting PII. I know this because when I traveled to Europe, my account on an adult website (gasp, yes I admit to having one) started asking me for ID. When I tried to proceed through verification with their chosen third party *the flow requested a video of my face*. Yuck. When I got back the US, it was still requesting face verification. I talked to support and, basically, once I used a French SIM card it "blew a verification fuse" and the only way to get my account back was to send that video of my face. I found this unacceptable, so I abandoned my account. If we refuse to find a workable solution that respects privacy and is based in open standards, we are going to cede this space to private third party companies.
- dns_snek 1y ago> if you're an average user (note: Hacker News users aren't average users) your ISP already knows which porn sites you visit, and your privacy is dependent entirely on your ISP not sharing that information with the government or other organizations. You're doing this thing where you pretend that public policy is only required to consider the average person's needs on their most average day. The same rhetoric can be used to argue against the vast majority of your personal freedoms. Imagine for a second that freedom of speech doesn't exist yet. If you're just like the average person who has nothing of value to say on the average day, then you don't need freedom of speech. Utilizing freedom of speech isn't the norm, therefore demanding it as a fundamental right is unreasonable. Nobody cares and why should they, they don't have anything important to say. Case closed. > If you look closely you'll see that none of your concerns are actually valid. No, you just severely underestimate the challenges of designing and implementing a system that would likely take many PhD-lifetimes of effort if you wanted to be confident that your implementation doesn't completely destroy whatever is left of our online privacy. You're potentially creating a digital panopticon, one that doesn't have any escape hatches like the current internet and yet you naively brush every concern away as "trivial" while your "solution" to one of the most pressing concerns depends on good faith collaboration from the website operator and even then incorrectly presumes that the Referer header is the only way that the government could possibly learn that information.