9 ms·
Welcoming Discord users amidst the challenge of Age Verification
- josefritzishere 8mo agoI'll be closing and uninstalling Discord the first time I get a face scan pop up.
- ranger_danger 8mo agoFWIW It's done on the client side and there are multiple ways to bypass it. https://news.ycombinator.com/item?id=46982421 https://news.ycombinator.com/item?id=46982421 https://tech.yahoo.com/social-media/articles/now-bypass-discords-age-verification-172757720.html https://tech.yahoo.com/social-media/articles/now-bypass-disc...
- edgineer 8mo agoThings are changing quickly. Some users are being allowed only 3rd party age verification. https://piunikaweb.com/2026/02/12/discord-uk-age-verification-persona-vendor-shift/ https://piunikaweb.com/2026/02/12/discord-uk-age-verificatio...
- jsheard 8mo agoThat K-ID bypass has already been patched, and even if it's bypassed again, Discord is apparently directing some users to Persona instead now. Persona does server-side classification so that one won't be as easy as nulling out the checks on the client. The 3D model method might work on Persona, but that demo only shows it fooling K-IDs classifier.
- direwolf20 8mo agoOh, so they promised your face was only processed on the client and then deleted, but none of that is true? They're courting some huge GDPR fines.
- jsheard 8mo agoEh, the worldwide rollout hasn't happened yet so for now the only people getting sent to Persona after they promised client-side scanning are those who are fiddling around with Discords internals to trigger the age verification flow early. But yeah if they stick with Persona then they will need to retract the client-side promise before the proper rollout, and that'll be even more fuel on the PR fire.
- ranger_danger 8mo agoI cannot even use Discord if I wanted to... every time I try to sign up I get immediately phone-walled and/or banned, and the appeal is always denied with "our automated system is working properly." I have been trying for close to ten(!) years now off and on, with all different combinations of browsers, OSes, ISPs and physical machines. No VPN or proxy either. And even if I was able to register, that "automated system" still randomly bans people whenever it feels like it. Search the r/discordapp subreddit or just google "discord random ban", it's a widespread problem with no solution and I have no idea how so many other people seem to have no issues, yet at the same time you can find lots of people just as frustrated as me.
- amluto 8mo agoOn the two occasions I’ve tried to chat with someone on the public Matrix server, I was completely unable to get it to work. I’ve tried with the new Mac app and with some older thing years ago. So… choose your poison? I’m sure Matrix/Element works for someone or they would be out of business, but it does not work for me.
- ranger_danger 8mo agoI have a similar issue with Matrix as well... even though it's federated, most large rooms use the same bots and blocklists so I end up getting banned from many rooms before I've even attempted to join. Apparently my monopoly ISP rotates IPs fairly often and I am sharing them with people that have been doing bad things with them, so not only are many Matrix channels blocked but even large regular websites like etsy or locals are completely blocked for me as well. Anything with a CF captcha is also an infinite loop.
- amluto 8mo agoAs far as I know I wasn’t banned or restricted or anything. The client just never managed to create a room or initiate a chat or whatever they called it.
- Terr_ 8mo ago
- genghisjahn 8mo agoThere's just something about that headline that doesn't land well.
- Bender 8mo agoI appreciate their effort but isn't Matrix (the company) based out of the UK and primary hosted instances on AWS in the UK? The UK were the first AFAIK to create such internet laws [0]. I could imagine people running their own instances in places where the age laws are not yet active but that number is shrinking fast. [1] Their solution is for everyone to pay for Matrix with a credit card to verify age. I assume that means there must be a way to force only paid registered accounts to join ones instance? What percentage of the accounts on Discord are paid for with a credit or debit card? Or boosted? I don't keep up with terminology [0] - https://en.wikipedia.org/wiki/Online_age_verification_in_the_United_Kingdom https://en.wikipedia.org/wiki/Online_age_verification_in_the... [1] - https://avpassociation.com/4271-2/ https://avpassociation.com/4271-2/
- Quothling 8mo agoCouldn't you simply set up your own instance and link up with the wider network? I guess you would have to age verify yourself if you live in a country that requires it, but regulating that would be sort of hilarious.
- Bender 8mo agoCouldn't you simply set up your own instance and link up with the wider network? I honestly have no idea. As much as they love money I am not paying my lawyers to research AI this one. I would probably wait for others to get made example of.
- foresto 8mo agoYes, you could. Whether or not authorities with jurisdiction over you would notice your instance (homeserver) or bother you about age verification is an issue you'd have to consider for yourself.
- codebje 8mo agoI'm more familiar with Australian legislation than others, but here at least a home server would definitely not require age verification. Kids are free to make group chats with their friends in a bunch of services. The spirit of the law is definitely not against chatting with friends, but it is against the idea of connecting minors with strangers, so while federation is generally not codified (or, IMO, understood well by legislators) and you're probably not going to be bothered by authorities about it, I reckon sooner or later the law will come for federated networks. (Since we all seem fine just taking some uncertified random third party's word for it that their AI face recognition definitely didn't see a thumb with a face drawn on it, maybe it'd be adequate for Matrix.org to add an "18+ user" flag to the protocol and call it a day?)
- xena 8mo ago[flagged]
- aystatic 8mo agoyou are literally on hackernews
- kelseyfrog 8mo agoElaborate?
- poly2it 8mo agoIs the implication that HN is transphobic?
- aystatic 8mo agoyou're free to have your own opinion based on your experiences here, but i wouldn't blame anyone for feeling that way. for the record, i don't think dang or anybody is a transphobe, but i have to imagine the culture here is pretty off-putting to trans people https://news.ycombinator.com/item?id=36231993 https://news.ycombinator.com/item?id=36231993
- oytis 8mo agoThis is a wild take. HN has transphobic users like it has trans and ally users. It's neutral to this topic, it's about tech.
- krapp 8mo agoThat isn't how it works. The presence of neutral allies doesn't somehow counterbalance and cancel out the transphobia. If a platform allows transphobic users - as Hacker News does because transphobia isn't against the guidelines - and transphobia is common in threads where trans issues or people are a subject (and it is) then it's a hostile platform to trans people. Asking trans people to ignore this is like asking Jews to be comfortable in a bar where only ten percent of the patrons are Nazis. Arguing that "well not everyone is a Nazi" doesn't help, an attitude of "we're neutral about Nazis, we serve drinks to anyone" still makes it a Nazi bar, just implicitly rather than explicitly.
- deleted 8mo ago[deleted]
- lenerdenator 8mo agoMy security collective is honestly considering going back to IRC. It's becoming increasingly apparent that if you don't use something truly free and open source and host it yourself, you're just setting yourself up for more of this sort of thing. You can't trust anyone to properly handle the problem of "how the hell do we keep creeps the f*ck away from kids?" with any amount of common sense.
- ranger_danger 8mo agoEven if you self-host matrix there are still multiple ways you could be liable for content you don't even know exists. Especially the last 4 points here: https://telegra.ph/why-not-matrix-08-07 https://telegra.ph/why-not-matrix-08-07 There are even custom message/media types that people use to upload hidden content you can't see even if you're joined to the same channel using a typical client.
- direwolf20 8mo agoHas this actually happened, or is it hypothetical? Was a server operator held liable for merely holding cached images? Edit: It seems I've suddenly been rate–limit banned.
- Arathorn 8mo agoThat post is 2023 vintage and is both outdated and questionable in parts. 19. "media downloads are unauthenticated by default" -> fixed in Jun 2024: https://matrix.org/blog/2024/06/26/sunsetting-unauthenticated-media/ https://matrix.org/blog/2024/06/26/sunsetting-unauthenticate... 20. "ask someone else’s homeserver to replicate media" -> also fixed by authenticated media 21. "media uploads are unverified by default" - for E2EE this is very much a feature; running file transfers through an antivirus scanner would break E2EE. (Some enterprisey clients like Element Pro do offer scanning at download, but you typically wouldn't want to do it at upload given by the time people download the AV defs might be stale). For non-encrypted media, content can and is scanned on upload - e.g. by https://github.com/matrix-org/synapse-spamcheck-badlist https://github.com/matrix-org/synapse-spamcheck-badlist 22. "all it takes is for one of your users to request media from an undesirable room for your homeserver to also serve up copies of it" - yes, this is true. similarly, if you host an IMAP server for your friends, and one of them gets spammed with illegal content, it unfortunately becomes your problem. In terms of "invisible events in rooms can somehow download abusive content onto servers and clients" - I'm not aware of how that would work. Clients obviously download media when users try to view it; if the event is invisible then the client won't try to render it and won't try to download the media. Nowadays many clients hide media in public rooms, so you have to manually click on the blurhash to download the file to your server anyway.
- cuillevel3 8mo agoFor everyone not reading the post: > Practically speaking, that means that people and organisations running a Matrix server with open registration must verify the ages of users in countries which require it. Last summer we announced a series of changes to the terms and conditions of the Matrix.org homeserver instance, to ensure UK-based users are handled in alignment with the UK’s Online Safety Act (OSA). At least you can self-host matrix and messages are end to end encrypted, unlike IRC.
- Bender 8mo agounlike IRC There are a few IRC clients that support OTR. irssi-otr is one [1] weechat-otr is another [2]. Pidgin though I have not used it in a very long time. Hexchat using an always work in progress plugin. There may be others. OTR could use some updates to include modern ciphers similar to the recent work of OpenSSH but probably good enough for most people. E2EE aside having chat split up into gazillions of self hosted instances makes it much harder for chat to be hoovered up all in one place. It takes more effort to target each person and that becomes a government scalability issue. Example effort: [3] [1] - https://github.com/cryptodotis/irssi-otr https://github.com/cryptodotis/irssi-otr [2] - https://github.com/mmb/weechat-otr https://github.com/mmb/weechat-otr [3] - https://archive.ph/4wi5t https://archive.ph/4wi5t
- progval 8mo agoLinks 1 and 2 have not had updates in 10 and 8 years respectively, they probably don't even compile anymore. They implement OTRv3 which was published in about 2005 and uses 1536-bits primes. As far as I know, neither the protocol nor the implementations were audited (and especially not audited recently). This is not good encryption at all. Additionally, OTRv3 does not allow multiple clients per account, which makes it unusable for anyone who wants to chat from two devices.
- Bender 8mo agoI use link [1] all the time. It comes pre-compiled for many Linux distributions but not installed by default. And yeah like I said it needs cipher updates like was recently performed in OpenSSH. HN has a handful of cryptographic nerds that could update OTR in their sleep if they so desired maybe even rewrite in Rust but being cryptographic nerds they probably have no need. If the same is true with cryptographers as is with car mechanics and plumbers they probably only use plain text as mechanics have broken down cars in their yards and some plumbers have old leaky pipes due to burn out.
- Aurornis 8mo agoThis appeal falls flat when you get to the parts about their homeserver requiring some form of age verification: > From our perspective, the matrix.org homeserver instance has never been a service aimed at children, which our terms of use reflect by making it clear that users need to be at least 18 years old to use the server. However, the various age-verification laws require stricter forms of age verification measures than a self-declaration. Our Safety team and DPO are evaluating options that preserve your privacy while satisfying the age verification requirements in the jurisdictions where we have users. Which is actually more strict than Discord's upcoming policy which allows accounts to operate for free without any verification, with some limitations around adult-oriented servers and content. There has been a lot of FUD about the Discord age verification, so a refresher: The upcoming changes do not actually require you to verify anything to use Discord. It just leaves the account in teen mode by default. This means the account can't join age-restricted channels, can't unblur images marked as sensitive, and incoming message requests from unknown users will go to a second inbox with a warning by default. You can, of course, run your own Matrix server. Having been there before I would suggest reading up on some typical experiences in running one of these servers. Unless you have someone willing to spend a lot of time running the server and playing IT person for people using it, it can be a real headache. They also note that running a server doesn't actually get around any age requirements: > Practically speaking, that means that people and organisations running a Matrix server with open registration must verify the ages of users in countries which require it.
- kennywinker 8mo agoExcept discord’s verification applies globally, while matrix is only aiming to implement it for users who live somewhere where it is required by law.
- puppycodes 8mo agoI wanted to love matrix and its clients but its just not quite there yet honestly. I'm hopeful the experience will improve in the future.
- kaboomshebang 8mo agoSame here, tried a couple of years ago. I was drawn to it because of the protocol concept. The experience was not bad, everything worked. But I remember the signup/domain/keys/backups/etc UX was a bit confusing. Happy to see there is more attention going to Matrix lately. Time to give it another go perhaps
- cuillevel3 8mo agoTotally agree there and they actually talk about that in the post: > Finally: we’re painfully aware that none of the Matrix clients available today provide a full drop-in replacement for Discord yet. All the ingredients are there, and the initial goal for the project was always to provide a decentralised, secure, open platform where communities and organisations could communicate together. However, the reality is that the team at Element who originally created Matrix have had to focus on providing deployments for the public sector (see here or here) to be able to pay developers working on Matrix. Some of the key features expected by Discord users have yet to be prioritised (game streaming, push-to-talk, voice channels, custom emoji, extensible presence, richer hierarchical moderation, etc).
- sregister 8mo agoLast time I tried matrix (~2022) they still didn't have voice channels--they had voice calls but not a mechanism where people can join/leave a particular voice chat at will. To me this is a must have feature for anyone who has used discord/mumble/ventrilo.
- wkrp 8mo agoI agree with you. The good news is that it looks like some of the alternate clients are focusing on it. https://commet.chat/ https://commet.chat/ has voice channels (video rooms but default to camera off), and cinny's element call support PR defaults to camera off in video rooms as well iirc.
- kuschku 8mo agoElement has had voice/video channels since late 2022 (though back then they only worked by enabling settings > labs > video rooms beta).
- xethos 8mo agoI was actually playing with voice rooms the other day. One can create a standing call room that people can join or leave as they see fit, without having to set up a new call each time. Discord currently has more integrations with streaming and voicechat rooms, but they had a bit of a head start, and even Element (let alone Commet & Cinny) are catching up
- rockskon 8mo agoI look at discussions on Hacker News for Discord replacements frequently with despair. If it doesn't have enough of the utility, performance, and positive UX, it will never gain enough market share to matter. E2EE encryption doesn't matter if you don't have someone else to communicate over it with!
- ddtaylor 8mo agoI was able to get setup with Stoat but it took hours for the verification email.
- Nannooskeeska 8mo agoMy verification emails never showed up from Stoat or Root.
- ddtaylor 8mo agoMine took 6 hours on Stoat.
- johnnyanmac 8mo ago>If it doesn't have enough of the utility, performance, and positive UX, it will never gain enough market share to matter. That's part of why billionaires will continue to screw people over. They will try and stay in bed with the familiar evil, rather than put up with the temporary inconvenience of freedom. And it's a negative spiral. Less users means less money to bring in staff which means less means to improve. Discord didn't become discord in a month, but other competitiors don't get that grace period.
- dang 8mo agoRecent and related. Others? Discord/Twitch/Snapchat age verification bypass - https://news.ycombinator.com/item?id=46982421 https://news.ycombinator.com/item?id=46982421 - Feb 2026 (435 comments) Discord faces backlash over age checks after data breach exposed 70k IDs - https://news.ycombinator.com/item?id=46951999 https://news.ycombinator.com/item?id=46951999 - Feb 2026 (21 comments) Discord Alternatives, Ranked - https://news.ycombinator.com/item?id=46949564 https://news.ycombinator.com/item?id=46949564 - Feb 2026 (465 comments) Discord will require a face scan or ID for full access next month - https://news.ycombinator.com/item?id=46945663 https://news.ycombinator.com/item?id=46945663 - Feb 2026 (2018 comments)`
- apopapo 8mo agoHas anyone managed to run Matrix over I2P or other similar overlay network technologies?
- xethos 8mo agoApparently yes [0]. I thought I'd seen a different post the other day, but this one was further up in a ddg search [0] https://tomsitcafe.com/2025/11/06/private-matrix-hosting-a-synapse-server-over-tor/ https://tomsitcafe.com/2025/11/06/private-matrix-hosting-a-s...
- b_brief 8mo agoAs a Discord user myself, I’ve been surprised at how aggressive the recent data collection direction feels, especially given how much of its appeal came from being lightweight and community-centric. This to me seems like a real opportunity for a simpler alternative that preserves core functionality without the additional data surface area.
- johnnyanmac 8mo agoI didn't see this specifically coming. But I saw this enshittification from a mile away the moment they changed leadership and how they immediately talked about wanting to IPO. It was never going to stop at aggressively pushing Nitro for this sort of c-suite >a simpler alternative that preserves core functionality That's practically a contradiction, sadly. The core features people want are all varied. You'd need 4-5 "simple" apps to replicate them all, but people want all their eggs in one basket.
- mmonaghan 8mo agoI just don't get why anyone is still arguing against age verification tbh. Large social spaces are required by law to do it, whether its discord or matrix or anywhere that allows strangers to interact.
- daft_pink 8mo agoI really wish they would just accept digital id’s from apple wallets for age verification without providing any identifying information somehow. It would be nice if we could use these digital wallets as a framework for all these things, annonymously.
- MitPitt 8mo agoThis can be done and it's called a zero knowledge proof (ZKP) in cryptography. And it's starting to be used in crypto wallets to verify humanity.
- thingification 8mo agoI think I've been waiting since the 90s hoping somebody will figure out how to make this a real thing (or was it the early 2000s?) As I recall it seemed to be just one guy, David Chaum, who did so much to show how so many of these things could work, but the rest of us have somehow managed to do very little with his ideas. What are we missing?
- johnnyanmac 8mo agoYou're missing a drive to make billions or wield power, silly. Of course there's always been ways to do this ethically. But the ones up top don't make money from that. And they can spend billions convincing people the only way it works is with whatever makes them money.
- daft_pink 8mo agoYeah, today I logged into Claude on my iPhone and it asked my approval for Apple to validate that my age range was “Adult” without providing any additional information. Why can’t this be used everywhere we are being asked to validate our age like adult websites/discord/etc?
- arjie 8mo agoWhat's the canonical way to block users from age-gate jurisdictions to one's website? I wish Cloudflare had a wizard flow for this. I'm not going to age-gate access to my blog (it's a wiki so it has user-generated content) so I'd rather jurisdiction-gate it. Perhaps we should have network traffic report its geographic location so that we can comply easily. Would prefer something in an IP packet so that I can just filter at the firewall. Doesn't even need to be implemented in a sophisticated way at clients. Can just have the urgent flag repurposed to mean "respond only if not geo-locked and unconcerned with regulatory" and then I can drop these directly, and regulated source locations could ensure that packet flags are correctly set at the widest peering location out of the UK and so on.
- veeti 8mo agoThis can be done easily with Cloudflare security rules, where you can match against country and block all requests.
- arjie 8mo agoOh thank you. I don't know why I couldn't find it but it's actually a near first class feature in WAF (select by country/continent and block). I think it's because I wanted to serve a blocked page, which is totally doable with Custom Pages or a Cloudflare Worker. Thank you! The right way is to serve a 451 page.
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- techbrovanguard 8mo agoYou can’t pay me to use Matrix, it’s irredeemable trash.
- shevy-java 8mo ago> Since then Australia, New Zealand and the EU have introduced similar legislation I am not aware that the EU pushed legislation onto us here in central Europe with regards to "Age Verification". I am not saying it has not happened (I simply don't know right now), but this needs a source rather than just a statement. From what I remember, local media in german critisized the UK, so it would be strange to see the same legislation suddenly come into effect here. Also, it seems we did not really win a lot if a private company operates matrix.
- throwaway473825 8mo agoThe EU will probably wait until the launch of a digital wallet that can do anonymous age verification. Otherwise it won't get enough political support.
- lyu07282 8mo agoI really doubt it because none of these efforts has anything at all to do with age
- DoingIsLearning 8mo ago> local media in german critisized the UK That's old news, now is all about "think of the children". This is too synchronous not to be arranged with the Commission. My vote is on Europol and Palantir lobbying. France - https://www.lemonde.fr/en/pixels/article/2026/01/31/social-media-ban-for-under-15s-why-everyone-in-france-will-soon-have-to-verify-their-age_6750002_13.html https://www.lemonde.fr/en/pixels/article/2026/01/31/social-m... Spain - https://english.elpais.com/technology/2026-02-04/is-16-a-good-age-to-limit-the-use-of-social-media.html https://english.elpais.com/technology/2026-02-04/is-16-a-goo... Denmark - https://edition.cnn.com/2025/10/08/tech/denmark-children-social-media-ban-scli-intl https://edition.cnn.com/2025/10/08/tech/denmark-children-soc... Portugal - https://www.reuters.com/world/europe/portugal-approves-restrictions-social-media-access-children-2026-02-12/ https://www.reuters.com/world/europe/portugal-approves-restr... Greece/Austria/Finland/Belgium/Italy also discussing. The best one for me is Portugal, parliament approved this law all while the country is being devastated by hurricane winds and flooding with several calamity zones. They are really bringing Law into effect by maximum obfuscation. EU anonimity online is over because ivory tower folks want to speedrun all of us into 1984. And this is obviously just a stepping stone to mass message scanning. The revolution will not be organizable.
- rixtox 8mo agoIt’s unfortunate that they claimed “Matrix is a protocol not a service” while they are literally running a home server on the Matrix domain. They should really rebrand their home server to another name, so the Matrix name is unambiguously referring to the protocol.
- Arathorn 8mo agothat would be a bit like w3c.org not running a web server on their domain…?
- rixtox 8mo agoBut no one is claiming w3c is not running a website.
- notepad0x90 8mo agoor just call their flagship client "Matrix" instead of Element. what's Element? it means nothing. it's like saying "item" or "thing".
- computersuck 8mo agoDoesn't sound that fking welcoming to me
- BrenBarn 8mo agoIt is really great to see a post from the Matrix Foundation that forthrightly acknowledges it is not ready for mainstream adoption and shows awareness of its limitations. I hope this is a good omen for the future of Matrix.
- notepad0x90 8mo agoIt seems both the Linux desktop and Matrix have the opportunity of a life time now. If they don't rise to the occasion and grab that marketshare, I fear there may never be an opportunity like this again.
- johnnyanmac 8mo agoLinux won't rise to the occasion because there's no figurehead leading the rise. Linux's greatest strength and weakness is in its breadth of a community. But that's not how you traditionally attract a mainstream audience. That's why Valve is the best chance here, and why I'm not too optimistic. Valve's incentives are to make its own walled garden, which in my eyes defies the idea of linux. But that seems to be the only thing that works these days.