7 ms·
> If you don't want to verify your age, you can still use its services - but it won't serve you porn or let people send you non-public messages. > I think that
by driverdan 1y ago
> If you don't want to verify your age, you can still use its services - but it won't serve you porn or let people send you non-public messages.
> I think that's pretty reasonable.
You lost me right there. Blocking DMs because of draconian age verification is not reasonable. There's nothing inherently problematic about DMs. Someone can be a creep in public just as easily as in DMs.
- billy99k 1y agoand just why is age verification 'draconian'?
- cess11 1y agoBecause it axes a liberty humans have enjoyed since we started talking to each other.
- tempfile 1y agoYour reply has been generated! In order to receive your reply, please complete a routine Age Verification check. To verify, simply post a copy of your government-issued ID into the comment box. FAQs: Q: Why should I give some stranger on the internet a copy of my government ID? A:
- maybewhenthesun 1y agobecause there is no way to verify someone's age without removing their privacy protections. No matter what politicians seem to believe it's just not possible. I've always taught my children never to use their real names online. Precisely to avoid creeps. Mandatory age verification means mandatory identification.
- edent 1y agoI don't think that's quite accurate. Most age verification services use either government providers or 3rd party providers. I show my passport (or whatever) to the third-party. They relay to the site "this user is / isn't over 18". They don't send the DoB, address, photo etc. So the online service only receives a binary yes/no and nothing else. I don't lose any privacy there. The third-party knows that you wanted to be verified on service xyz, but not what you do there. Depending on the service I'm using, I may or may not care that they know. Handing over a passport / licence to get into a bar leaks more information than that.
- itake 1y agohow long does the bar retain access to your ID? how can you trust 3rd party providers?
- edent 1y agoI don't know if you've been to a bar recently. Lots of them stick IDs in a scanner. I handed over my passport to a hotel recently, they took it away and photocopied it. I'd rather trust an organisation which stakes its business on being secure than handing over my ID to anyone.
- wkat4242 1y agoI have never been 'carded' in a bar in my life. Maybe that's a US thing. Bars here are required to make sure you're old enough but if it's obvious they don't have to card anyone.
- itake 1y agoits definitely a US/CA thing. The penalties of serving alcohol to under aged are high, potentially losing your license to sell alcohol. Regulators perform random checks with plants to verify proper protocols are followed.
- pjc50 1y agoYou've just leaked your identity to the third party! These third parties tend to be US based, as well. That always raises privacy questions due to "Safe Harbor". It was completely stupid of the government not to even provide a UK age verification service before putting this in place.
- edent 1y agoIt isn't a leak if you do it intentionally. There are lots of age-verification providers in the UK / EU. The industry had plenty of notice this was coming and reacted accordingly.
- CaptainOfCoit 1y agoI'm not sure if you work in software or not, but it's definitely possible to come up with a schema where you could verify people's age in order to use a platform, without exposing your entire identity to said platform, with a combination of signatures and other cryptographic basics. Say you have a digital certificate from the government or similar that you use to do your taxes online or whatever, the government could have endpoints where you could use that certificate for signing a proof, that you then hand over to the platform you want to verify your age with. The platform can then confirm it's valid, and that $AGE>X, but they get no other details. You can even go a bit fancier/more complicated, and the government endpoints wouldn't know what platform you're trying to verify.
- sleepychu 1y agoHow do I prevent my citizens from sharing their certificates in order to bypass the block?
- CaptainOfCoit 1y agoYou don't, it's up to citizens to make sure whatever authentication they use can only be used by them, just like how it works for other services today where you authenticate online somehow and the government service assumes you're you since you were able to authenticate.
- sleepychu 1y agoMy point is that this is either a bearer token (in which case it will be obtainable by proxy) or tied to your identity. What is the incentive for the citizen to make sure their authentication isn't shared?
- owisd 1y ago> obtainable by proxy So no different to the rules around buying an 18+ DVD.
- CaptainOfCoit 1y ago
- tzs 1y agoThat's not correct. With a government issued signed digital ID cryptographically bound to a hardware security module you can use a zero-knowledge proof based protocol to prove to any third party site that (1) you have a signed government ID, (2) you have the hardware security module that it was bound to when the government issued it to you, and (3) the date of birth field on that ID says you are older than the site's age threshold. This reveals no other information to the site. The EU is on track to deploy such a system by the end of 2026. They are currently doing field testing involving thousands of users.
- thescriptkiddie 1y agozero-knowledge proofs don't work like that
- tzs 1y agohttps://eprint.iacr.org/2024/2010 https://eprint.iacr.org/2024/2010 https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/blob/main/docs/annexes/annex-B/annex-B-zkp.md https://github.com/eu-digital-identity-wallet/av-doc-technic... https://blog.google/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/ https://blog.google/technology/safety-security/opening-up-ze... https://news.ycombinator.com/item?id=44457390 https://news.ycombinator.com/item?id=44457390
- immibis 1y agoYup. For $5 (hypothetically) I'll use my ID to make that ZKP for you, and you can pass it to the site.
- ranger_danger 1y agoBut it still doesn't prove that the person creating the proof is the person who was assigned the government ID, right? What's to stop someone from using their ID to power a bunch of bots? And AFAIK unless the company has a database/API for all the existing IDs in the world, I would think it doesn't stop forged IDs from existing. And even then, corrupt employees could still issue forged IDs... there's no guarantee that a single ID equals a single person forever.
- dpark 1y agoSo what is the problem? I don’t want my kids sharing real names online. I wouldn’t want them verifying their age with Bluesky either. But that’s fine because I also don’t want them getting porn or DMs on bluesky. This is win win for kids. It’s not a win for adults who now have to expose their identity.
- gjsman-1000 1y ago[flagged]
- immibis 1y agoI think people just don't want the government to surveil everything they do.
- gjsman-1000 1y agohttps://news.ycombinator.com/item?id=45430811 https://news.ycombinator.com/item?id=45430811
- Aloisius 1y agoEm. Thomas Paine, James Madison, Alexander Hamilton, John Jay, Benjamin Franklin, John Marshall, John Locke, Immanuel Kant, David Hume, Baruch Spinoza, René Descartes and many, many more wrote anonymously. Some wrote anonymously because they wanted the words to speak for themselves, such as Madison, Hamilton and Jay writing the Federalist Papers. Some did it because they thought their name might detract from the message - such as Franklin's writings when he was a teenager. And some others did it to avoid consequences for their opinion - such as when Thomas Paine penned the case for American independence - literally treason. Even Paine's publisher, Benjamin Rush, remained anonymous! The idea that free speech without responsibility wasn't a consideration seems contradicted by how utterly pervasive it was by classical liberal philosophers and founding fathers and how influential those writings were to the founding of the country and the creation and passage of the first amendment.
- Ajedi32 1y ago
- gsich 1y agoBecause I don't trust any company with handling such verification.
- 1970-01-01 1y agoDMs can come from anywhere, globally. This is much different than a public space with limited levels of users and police dispensing arrests on problematic users.
- itake 1y agoletters, phone calls, and sms can come from anywhere, globally. There is no middle man reading every message and blocking anything it doesn't like.
- firtoz 1y agoIf you don't adhere to rules with phone calls and SMS you will get identified very quickly by authorities. That's the point, they have the infrastructure set up like that. For letters, it's a bit different, but if they suspect someone or something they can indeed track things down.
- f33d5173 1y agoThey can track down the origin of a ip packet as well. To rejoinder the response of "what about vpn" - sms, phone, and letters can all be proxied as well.
- TheDong 1y agoProxying network traffic is wildly easier. The tor project was built specifically to ensure anonymity for internet traffic, and it works well as far as I know. Phone numbers are not the same, countries require you to verify your identity to sign up for a phone plan, most sane countries have a government identity tied to each and every phone number, and proxying doesn't change that. The US is weird in that it has some anti-government-identity stance that makes this way less centralized, but regardless, phone numbers are mostly traceable, there's nothing like tor, and the law also treats sms as more traceable. Phone plans also cost at least something to sign up for. I will give you that physical letters can be anonymous, but due to postage stamps it's much more expensive to send them in excess.
- edent 1y ago"Hey buddy! You're right. And so mature for your age!" The reason OSA puts DMs in scope is because they are out of view of the public. If you start creeping on someone where it is viewable, people will call you out. If you do it in private it becomes "our little secret". That's how groomers work. Go talk to any kid blackmailed into doing something they didn't want to do. It often starts with private messages.
- yard2010 1y agoTbf this won't solve this horrendous issue but create a new problem just like the stupid cookie banner fiasco.
- computerthings 1y ago[dead]
- hk1337 1y ago> Someone can be a creep in public just as easily as in DMs. I would argue that one could be MORE of a creep and lewd in DMs than in public.
- Aurornis 1y ago> Someone can be a creep in public just as easily as in DMs. Definitely not true. Public messages risk a wide audience seeing the message and recognizing it’s inappropriate, then taking action against the person, reporting them, or highlighting the inappropriate messages for mob reprisals. This is why predators overwhelmingly prefer private messaging where they can control visibility of their actions to a single vulnerable target.
- SuperShibe 1y ago>Public messages risk a wide audience seeing the message Anyone can easily circumvent this by using asymmetric cryptography to encrypt their messages.
- Aurornis 1y agoNobody is going to the trouble of getting their target to set up cryptography tools so they can pass private messages back and forth between public channels. They're going to move to another platform where they can find targets who have DM functionality available. BlueSky's job is done.
- SuperShibe 1y agoNo one is going to the trouble of getting their target to GDPR-request their private DMs as well. This misses the point of the blogpost.
- tracker1 1y agoHaving to delete the obvious spam "hello" DMs in Telegram is so much fun... Fortunately I'm not that active and only in a couple channels. I still see a couple a day (block/report, etc).
- SV_BubbleTime 1y ago>risk a wide audience seeing the message and recognizing it’s inappropriate As everyone knows, risk is unacceptable! And inappropriate is of course an objective classification.
- jrm4 1y agoLook, DM's are inherently stupid. Just let people post their email addresses and contact THAT way. Now, of course, I'm not naive -- I understand that this idea is extremely unlikely to catch on and we're probably well past it. But still going to put it out there because I think it makes the most sense.
- extraduder_ire 1y agoI read that as bluesky's response to the UK law being reasonable, not that the law itself is reasonable.
- nomel 1y ago> There's nothing inherently problematic about DMs. You should definitely talk to some women. They generally have a drastically different, dick filled, experience with DMs. Multiply that by the felonies involved with interacting with a minor, the legal requirements of COPPA, and the PR problems of things like "grooming groups found on <platform>", and the problems become more clear. Of course, the real issue is parents giving their children unrestricted access to the internet.
- dpark 1y ago> Of course, the real issue is parents giving their children unrestricted access to the internet. I agree and yet blaming negligent parents doesn’t help the children. These sorts of mandates don’t make any sense when I think about my kids, who have devices quite locked down. These sorts of mandates make a lot of sense when I think about all the kids who have unfettered access to the worst parts of the internet.
- southernplaces7 1y agoThat the wider world of millions of adults should have an infantalized version of internet be their only option unless they completely sell their privacy down the river in the most fundamental sense because some parents can't watch over their children's digital access is a grotesque justification for mandatory age verification. This aside from the question of just how fragile many minors are if "exposed" to things like porn. Anecdote of course, but I was able to view all kinds of dirty stuff well before I was of legal age in my country, and who can forget the now legendary rotten.com website, as just one example. None of this made me or any of my many friends at the time turn into raging pedophile serial killer schoolshooter psychopaths. These sorts of proposals are in part a rehashing of the utterly idiotic blame game against video games for cases of truly disturbed minors who ended up committing mass murders in the past. Some people are just going to end up badly disturbed by default or much more systemic causes like a bad home. A mass sanitization of all possible sources of content and media applied to everyone unless they consent to X or Y heavy intrusion won't change that.
- nomel 1y ago
- horuscrux 1y agoOh no; lost you... of all people. Others devices are not public property.