6 ms·
The real and robust method will be generating artificial video input instead of the real webcam. I really don’t think any platform will be able to counter this.
by cocoto 8mo ago
The real and robust method will be generating artificial video input instead of the real webcam. I really don’t think any platform will be able to counter this. If they start requiring to use a phone with harder to spoof camera input, you will simply be able to put the camera in front of a high resolution screen. The cat and mouse game will not last long.
- jsheard 8mo agoThey already support ID checks as an alternative to face scanning, if the latter proves to be untenable then it's literally a case of flipping a switch to mandate ID instead.
- Forgeties79 8mo agoMost people under the driving age don’t have ID’s, at least in the US.
- airstrike 8mo agoAnd lose every user in the process
- dark-star 8mo agoI think you massively overestimate how many people actually care. My guess is that 95% or more of all Discord users do not care and simply upload their selfie or ID card and be done with it. I know I will (although they did say that they expect 80%+ to not require verification since they can somehow infer their age from other parameters)
- bee_rider 8mo agoThose 5% are the unusual sorts that separate Discord from Facebook.
- esseph 8mo ago> I know I will Are you a minority, LGBTQ+, etc or of a "different" political persuasion that might have any reason to be distrustful of the US government? If so, you probably wouldn't just "be done with it".
- dark-star 8mo agoNo, I'm not, and I also don't live under an opressive government that tracks those people down. I simply don't care if the us government or some random US company knows about what I play, eat, talk about or who I sleep with. And my guess is that outside the US LGBTQ+ and "different political view" bubble, most people also don't care. And that bubble makes up maybe 5% of Discord's user base
- int_19h 8mo agoThe real question is, how much of the "terminally online" population who is more likely to use paid Discord features?
- airstrike 8mo agoRemember digg? I've already cancelled my Nitro account. I'm quite active on a ~5k member programming server and we're giving Zulip another try. I think it's unlikely we'll stay on Discord. Obviously anecdotal, but eventually this adds up.
- deleted 8mo ago[deleted]
- lossyalgo 8mo agoAlso cancelled my Nitro after 5 years. This whole thing being "for the safety of kids" is obviously a farce just to get more user data because Nitro users supposedly will have to do the ID check as well, but if you're paying with a CC/Paypal, you are obviously of sufficient age to not require an ID check.
- jasonfarnon 8mo agoIs there any data on what kind of hits to enrollment were taken by facebook, gmail etc when they added requirements like a phone #? Maybe it's buried in their sec filings.
- jasonfarnon 8mo agoIs there any data on what kind of hits to enrollment were taken by facebook, gmail etc when they added requirements like a phone #? Maybe it's buried in their sec filings. Anyway, this "cat and mouse" game is probably irrelevant. They're not looking for and don't need a perfect system. Bc 99% of the public couldn't care less about handing over their information.
- drnick1 8mo agoGoogle does not require a phone number. They may ask for one and tell you it's for your own good, but you can skip the request.
- arcologies1985 8mo agoThey can't feasibly do this in the US since many people don't have drivers licenses or passports.
- carcabob 8mo agoThose without driver's licenses or passports can get a state ID card instead, if I'm not mistaken. A pain, but an option.
- efreak 8mo agoIt's actually not a pain. It's the same process as getting a driver's license, minus the test. You go into the DMV and wait in the same lines (at least in California; I have a CA state ID, not a license)
- jsheard 8mo agoDon't you have to be over 18 to get a credit card in the US? How many wouldn't be able to present a CC or ID?
- Denatonium 8mo agoOnly to have your own card. You can be an authorized user on a credit card even if you're under 18.
- jsheard 8mo agoAh right. That's no use for verification then, unless there's a way for payment gateways to distinguish the primary user from their authorized users.
- Gigachad 8mo agoAt least in Australia you absolutely can have a debit card under 18 and it’s extremely common for adults to not have a credit card.
- alright2565 8mo agoID is much easier to forge, it's just a flat 2-d shape. None of the physical security features come through in images.
- junon 8mo agoWhen I had to prove my passport for my bank over a video call they told me to rotate it around in the sunlight to show that it had the holo-whatever ink. So I wouldn't put it past them.
- digiown 8mo agoA call requires a human, which is inherently not scalable. And even humans have trouble distinguishing AI content these days.
- ziml77 8mo agoAnd it's not like Discord actually cares. They just care about appearing like they care. Something to keep the heat off of them from regulators and angry parents.
- uncletscollie 8mo agoDiscord built its own TSA?
- krisoft 8mo agoA “video call” perhaps requires a human, but the type of test described need not be a video call. One can imagine a network trained to distinguish a fake id card from real one from a video recorded where the user is asked to move the card such that the holograph is glinting in the sunlight.
- TheDong 8mo agoIn functioning states, the ID contains a chip with a private key that can be used to sign a message, and ID verification would not be an image of the ID card, but rather holding your phone's NFC reader to the card and signing a message from the site. In Japan, there are already multiple apps which use something like this to verify user's age via the "my number card" + the smartphone's NFC reader. It's more or less impossible to forge without stealing the government's private keys, or infiltrating the government and issuing a fraudulent card. Of course, the US isn't a functioning state, the people don't trust it with their identity and security and would rather simply give all their information to private companies instead.
- beambot 8mo agoPersonal Identity Verification (PIV) and Common Access Card (CAC) credentials used by US government & military via NFC already work on web browsers. States should just move to digital IDs stored on smartphones, with chain of trust up through the secure element...
- esseph 8mo ago> Personal Identity Verification (PIV) and Common Access Card (CAC) credentials used by US government & military via NFC already work on web browsers. States should just move to digital IDs stored on smartphones, with chain of trust up through the secure element... I think you're... missing the point of the pushback. People DO NOT WANT to be identified online, for fear for different types of persecution.
- drnick1 8mo agoThis is extremely dangerous, and would only work with hardware/software that is nonfree (i.e., not under the user's control, or any attestation could be spoofed).
- beambot 8mo agoThis is effectively PKI for personhood. The State DMV acts as the Certificate Authority (CA), signing a "leaf certificate" that is bound to the device's hardware Secure Element. It’s less like a TLS handshake and more like OpenID for Verifiable Presentations (OID4VP). The "non-free" hardware requirement serves as Remote Attestation—it allows a verifier to cryptographically prove that the identity hasn't been cloned or spoofed by a script. The verification happens offline or via a standard web flow using the DMV’s public key to validate the data signature, ensuring the credential is authentic without requiring a phone-home to the issuer.
- esseph 8mo agoSo centralizing control over personhood. Got it.
- Gigachad 8mo agoThe long term solution would have to be some kind of integration with a government platform where the platform doesn’t see your ID and the government doesn’t see what you are signing up for. I don’t this will happen in the US but I can see it in more privacy responding countries. Apple and Google may also add some kind of “child flag” parents can enable which tells websites and apps this user is a child and all age checks should immediately fail.
- Barrin92 8mo agothis is already how the EU infrastructure for digital ID works, basically. Using public/private keys on your national id, the government functions as a root authority that you (and other trusted verifiers downstream) can identify you with and commercial platforms only get a yes/no when you want to identify yourself but have no access to any data. South Korea also has had various versions of this even going back to ~2004 I think.
- Semaphor 8mo agoDo all EU countries have that? I know our (German) ID works that way, using the FOSS AusweisApp, but I hadn’t heard of it being EU-wide (it should be, though).
- fcatalan 8mo agoSpanish ID cards have had an X. 509 cert inside them for more than 10 years, I use it all the time to sign documents and access government sites. There is already legislation and a push for an EU-wide digital identity wallet that should be up and running this year, look up eidas 2.0 and the EUDI wallet. That looks like it should make things like privacy compatible age verification "trivial".
- Semaphor 8mo agoThanks, that looks very cool, and apparently close to coming into effect.
- sieabahlpark 8mo ago[dead]
- EGreg 8mo agoActually, there are many ways. For example they change colors on your screen and check in real time how it reflects on your face, eyes, etc. Very hard for a model to be trained to respond this quickly to what's on the screen. They also have you move your head in multiple directions.
- cocoto 8mo agoYou could always generate a random face model with real time rendering with enough details to trick any AI detector (or even human) and then you can do real time animation to orders or screen light tricks. You could also simply use some face filter on your face and these ones are really convincing these days (like on Snapchat and such).
- EGreg 8mo agoShow me such a model. It would be interesting to see a model completely indistinguishable from a real human in behavior, as well as real-time reflection off different surfaces, etc. The next step would be to make a complete digital clone of a person based on surreptitiously recording them with hidden cameras. I doubt it's possible.
- ddtaylor 8mo agoThis is doable using high end stuff like Runway with a draft quality. Your better bet would be to generate a face as an image and then you can easily generate that same face in different expected poses and conditions. You can then use existing models where you get to select the starting image and the ending image. Add some filters and noise to just make it look like normal crappy low light camera. As for the color that's another expected condition and can be overlayed or pre-generated.
- viraptor 8mo agoThe pieces are there. If you're not modifying everything in the image all the time, there's no reason to run it through a visual model. Generate it once (we have it), transform into textured 3d model (we have it), animate and map to movements with vtuber software (we have it). Adding screen colour reflection is trivial. We just need a pipeline for this. We had facerig for over a decade now. Facefilter recently. It's not hard anymore.
- toomuchtodo 8mo agoYou require a human to identity proof in real life and bind that to a digital identity with a strong authenticator. Anti fraud detection systems can suspend or ban if evasion attempts are detected. Perfect is not the target, it doesn’t have to be. See: Login.gov (USPS offline proofing) and other national identity systems. (digital identity is a component of my work)
- gruez 8mo ago>You require a human to identity proof in real life and bind that to a digital identity That's going to be a no from me, dawg. I'm sympathetic to ID checks like if you're buying beer or whatever, but not linking my real life identity to discord or whatever.
- toomuchtodo 8mo agoNot my call, it’ll be the law of the land. Some may leave, but most won’t, and that’s good enough for corporate and enterprise value purposes. Pornhub is fighting state age verification and keeps losing state by state, for example.
- toomuchtodo 8mo agoPorn site fined £800,000 for not rolling out age checks - https://news.ycombinator.com/item?id=46990755 https://news.ycombinator.com/item?id=46990755 - February 2026
- wileydragonfly 8mo agoWhy should anyone inclined to want to buy beer have to show ID to do it?
- toomuchtodo 8mo agoBecause you’re required to in all 50 states to prove you’re over 21.
- kevinh 8mo agoAlternatively, hand someone $20 and your phone and have them do the verification for you.
- gnarbarian 8mo agoyou counter this by using an id verified service like login.gov or okta verify. That's the endgame and what the EU really wants. No poasting unless they can arrest you for inconvenient memes.
- leftouterjoins 8mo agoYes this is spot on. Apple & Google mobile platforms are locked down tight for this reason. Try installing okta verify on graphene OS. You cannot.
- deleted 8mo ago[deleted]
- monksy 8mo agoThey're getting worse with attested and validated environments. This one of the reasons that google is trying to kill sideloaded apps and checking for root access. Weird thing.. the people who want this validation fully expect for you to pay for, maintain, keep it valid, and pay for upkeep/service for their desires. Honestly, this is something that SHOULD get very aggressive pushback.. but most people accept for no reason.
- Nifty3929 8mo agoIt's not "accepting" - it's actual wanting. Many people want surveillance. Many people want age verification.
- uncletscollie 8mo agoA vague answer that says nothing and can't be proven. Thank you for wasting our time.
- apeters 8mo agoWow. The EU.
- tjpnz 8mo agoDeath Stranding 2 photo-mode works well for this.
- gclawes 8mo agoDon't Windows Hello camera devices have some kind of hardware attestation? I'm sure verification schemes like this will eventually go down that path soon. My guess is that's probably one of the reasons Google tried to push for Play Store only apps, provide a measurable/verifiable software chain for stuff like this.
- OptionOfT 8mo agoYes they do. Part of the reason why you can't use certain webcams that are Windows Hello compatible (I.e. with IR) in recent versions of Windows.
- nitwit005 8mo agoThat the camera is real doesn't imply the thing it's viewing is real.
- michaelt 8mo agoAs I understand it, 'Windows Hello' requires a near-IR image alongside the RGB image. It's not the fancy structured light of phone-style Face ID, but it still protects against the more common ways of fooling biometrics, like holding up a photo or wearing a simple paper mask.
- nitwit005 8mo agoFair enough. That removes the virtual option, and you'll be forced to point the camera at your older brother.
- kulahan 8mo agoYou're not wrong, but I have had to do video verification over a phone once, and it seemed quite advanced. It would flash through a number of colors and settings and take probably 30 frames of you. I presume they're checking for "this came from a screen and not a human", but of course I have no idea how it works, so I don't know if it's truly sophisticated or not.
- 8mo ago
- ddtaylor 8mo agoI did this with OBS Virtual Camera for a thing in Oregon and it worked.
- qwertox 8mo agoyou put a flickering light, pwm creating artifacts in the video and have it apologize for it, to hopefully break some watermarks. my led light started acting up since yesterday, i have no other bulb.
- bob1029 8mo agoThey could do what a bank does and run everyone's ID through chexsystems. It's really hard to defeat this. Fake identities don't exist in the system and stolen ones would get flagged by geographic, time of use and velocity rules.
- decimalenough 8mo agoDoesn't work for places like Australia, where the social media ban applies only to under-16s. Teenagers rarely have ID, especially in countries where the minimum driving age is higher than 16 (read: most of the world outside the US).
- bob1029 8mo agoThe concept of identity doesn't necessarily have to be embodied by a piece of physical plastic that goes into a wallet. Ad-hoc identification can occur via other means like dynamic knowledge based authentication. The sources of this mechanism can be literally anything. Social media itself being one obvious source for the target cohort. You can walk into many US financial institutions without an ID and still get really far using KBA workflows. The back office will hassle you for a proper scan of a physical ID, but you can often get an account open and funded with just KBA.
- michaelt 8mo agoKnowledge-based authentication is a joke - it doesn't work at all. This basically only gets used for businesses that need a fig leaf for regulatory purposes. You know, $30 loans for uber eats and tiny loans like that.
- RupertSalt 8mo agoUnix and Windows and MacOS and every computer since 1970 has relied on knowledge-based authentication, so let's cool the hyperbole. In the nomenclature of Multi-Factor Authentication, "something you know" is one factor. So if you know a password and you have a hardware token, that's 2 factors and combining different types is the key to MFA. Many "knowledge based authentication" tries to string together "things you know" without a different type, and that's a weakness. However, it can be strengthened through various techniques. If a human is authenticating you in real-time, they may choose a factoid that an impostor is unlikely to know which may be agreed in advance. For example, the security questions combined with other challenges, or a "curve ball" that may elicit a stutter, pause, or prevarication. This is a dynamic method that bob refers to. In fact, knowledge-based quizzes are used routinely by credit reporting agencies -- the big ones like Experian. And they've been presented by background check services, too. They work like this: they scrape your credit reports and public records in a deep dive for your old addresses, employers, contact info, a whole smorgasbord of stuff. Maybe attackers know some of it. But it's multiple choice: "which of these did you live at? None of the above? All of them?" "Which one of these wasn't your employer?" And the attacker would need to have the same list of public records, and also know the wrong answers! Knowing the wrong answers is the "curve ball" here! How many attackers know that I didn't work for Acme, Inc, and I never lived in San Antonio? It's also worth pointing out that I've opened at least 3 bank accounts without setting foot in a bank. Even if yours is brick-and-mortar, they probably have a flow on their website for account creation and funding. It is not difficult to satisfy their ID requirements. If they glitch, then you're just flagged a bit, and you follow up as instructed. I've also authenticated identity to the federal government agencies, and accessed several DMV services, using only the apps and websites. People may feel reticent about establishing their identity online, but isn't it better that you do it first before someone else does? If your identity is known and registered and builds up data points that correspond to you, aren't you less likely to be a victim of fraud or identity theft when things don't add up?
- michaelt 8mo ago> I really don’t think any platform will be able to counter this. Do platforms want to counter it? Seems to me with an unreliable video selfie age verification: * Reasonable people with common sense don't need to upload scans of their driving licenses and passports * The platform gets to retain users without too much hassle * Porn site users are forced to create accounts; this enables tracking, boosting ad revenue and growth numbers. * Politicians get to announce that they have introduced age controls. * People who claimed age checks wouldn't invade people's privacy don't get proven wrong * Teens can sidestep the age checks and retain their access; teens trying to hide their porn from their parents is an age-old tradition. * Parents don't see their teens accessing porn. They feel reassured without having to have any awkward conversations or figure out any baffling smartphone parental controls. Everyone wins.
- internetter 8mo agoUntil somebody (likely a politician or anti-porn advocacy group) decides to poke the bear and ruin it
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- lisamay8879 8mo ago[dead]
- nofriend 8mo agoIt depends. If the law says "you must perform such-and-such steps to verify age" then no, they don't care if you can counter it. If the law says "you must use an approach that is at least x% effective" then yes they do care if enough people counter it. We already had a half-assed solution, where websites would require you to press the button that says "I am over 18". Clearly somebody decided that wasn't good enough. That person is not going to stop until good enough is achieved.
- TheDong 8mo agoThere is an easy solution to this - require a government ID, and only permit government IDs that can be verified with the state's government. There are a lot of countries and US states where such validation is possible. Given the state is mandating these checks, it only makes sense that the state should be responsible for making it possible to perform these checks.
- darth_avocado 8mo agoRemind me again, why do people need government approved ids to access discord in the first place? Everyone in this thread is solutioning how we could make government ids work, but no one seems to be asking if that’s a good idea.
- samename 8mo agoManufacturing consent at work
- subscribed 8mo agoBecause governments really want people to think about children with naughty stuff. Gross. (I'm not verifying anywhere unless required for official business. Still have my non-KYC sim for people)
- duskdozer 8mo agoWell, certainly not for linking all of your online activities with your real life identity of course, not sure where you got that idea from. It's to protect children. And of course, just in some very limited anti-terrorism cases...
- imtringued 8mo agoI've heard a politician explicitly request a real name policy on all internet platforms in Germany. Obviously the goal is always mass surveillance.
- darth_avocado 8mo ago> The cat and mouse game will not last long. Yes but for completely different reasons: I will not bother to play the game and stop using the platform.
- wiredpancake 8mo ago[dead]
- geniium 8mo agoThis is the right question. Who will benefits from blocking young people? Probably not the platform.
- lazzlazzlazz 8mo agoApple is believed to be adding multispectral imaging to future generations of the iPhone. This and 3d mapping are more than enough to defeat the "point the camera at a high res screen" trick. The issue is that age verifiers (like Discord) are not really trying.
- shevy-java 8mo agoBut how many users will do so? 1%? 5%? Also, they will probably find that out, and the moment people do so, they become suspicious to state actors. I understand the rationale behind the work around you described; I just don't think it will be a huge factor. I see this elsewhere too - for instance, I use ublock origin a lot. But how many people world wide use it? I think never above 30%, most likely significantly fewer (or perhaps all anti-advertisement extensions, I think it most definitely is below 50% and probably below 30% too).
- deleted 8mo ago[deleted]
- nicman23 8mo agohardware attestation webcams :) . in the dark future of the 2k there is only windows
- zjaffee 8mo agoThere's no need to counter it, the whole point is to hit the social aspect of being on these platforms. If even half the kids can't figure out how to make it work, then a massive part of the problem is solved because a much larger percentage are only using it due to network effects.
- mudkipdev 8mo agoIf it was that easy, Face ID wouldn't be used
- vagab0nd 8mo ago> you will simply be able to put the camera in front of a high resolution screen Are you sure it's that simple? How high does the resolution need to be for the camera to not be able to tell? And I'm sure there are sublet clues. Remember, you can't modify the photo or change the camera.