6 ms·
In my ideal world a law would: 1. Require device manufacturers to allow the device owner (which covers parents of minors' devices) to set policy for the device
by advisedwang 8mo ago
In my ideal world a law would:
1. Require device manufacturers to allow the device owner (which covers parents of minors' devices) to set policy for the device, including allow/blocklist for apps and sites, and allow/blocklists for content categories.
2. Require browsers to respect the device's policy for site allow/blocklist
3. Require browsers to set a certain header for allow/blocklist of content categories
4. Require websites to respect that header.
No need for age verification, no need for the government to decide what is/isn't allowed and for free you allow gamblers to prevent gambling content being shown to them etc.
---
This AZ law is frustrating because by targeting the app store it's actually taking a step towards my vision... but in a way that multiplies the harm of age verification instead of diminishing it.
- varispeed 8mo agoBut how corrupt politicians will make money having such reasonable policies?
- autoexec 8mo agoThe goal of these laws isn't to protect children, they just want to further surveillance and control of the population. While there are better ways to handle the "think of the children" concerns being invoked to justify these kinds of laws none of them would satisfy the legislators pushing them.
- munk-a 8mo agoThe problem is that we'd all blocklist advertisers and then they'd all cry. It's like how most mobile distros don't allow you to control relative app volume - if it might hurt ad bucks it can't be allowed.
- advisedwang 8mo agoGood point. I originally thought this would just be content categories. Maybe that's all that's plausible.
- drakythe 8mo agoAll the people with money would lobby against content categories because then large mixed category sites like Reddit or Twitter would have to either separate their app, or have the ability to send additional content headers based on content tags per piece of content. Legally, since pornography still doesn't have a true definition in the US, someone would have to define the categories as well, and then the hundred million free speech fights would begin. Your vision is the correct one, in my opinion, "adult content" headers would be an easy lift for web technology. But the ad agencies and information agencies (often the same) are spending all of the money to make sure nothing like that happens.
- advisedwang 8mo agoI've seen numerous apps that do already provide content categories without separating apps. NSFW/SFW is the most common, but I've also seen ones that allow you to opt-out of gambling or alcohol ads.
- handedness 8mo agoYou say that like it's a bad thing.
- LoganDark 8mo agoRemember: Advertisers cry with money.
- jonhohle 8mo agoThey’ve proven themselves to be bad actors with no moral compass. No different than street drug dealers, casinos, traffickers, or any other predatory industry. They should’ve regulated as such. I don’t have any problem with old-timey “Dishsoap Brand Dishsoap sponsored this content. They want you to know that a dish isn’t clean unless it’s Dishsoap clean!” Type ads. Much beyond that should no longer be tolerated.
- LoganDark 8mo ago> I don’t have any problem with old-timey “Dishsoap Brand Dishsoap sponsored this content. They want you to know that a dish isn’t clean unless it’s Dishsoap clean!” Type ads. Much beyond that should no longer be tolerated. I think the only advertising I've knowingly listened to was a Privacy.com sponsorship on The Modern Rogue. Now been a paying customer for years and they have been mostly great. I think that sponsorship was back in, like, 2015 or 2016. Oh how times have changed. (I'm sure there are thousands of subconscious influences that I have no idea about, though. Maybe a few radio ads put a brand in my mind for something so I didn't search for alternatives. I don't listen to broadcast radio anymore though.)
- munk-a 8mo agoHeck no - I own a Samsung purely to continue to have access to Sound Assistant (to enable individual app volume control without rooting my device). I just want everyone to be clear on why it isn't happening. This is also the same reason why early versions of Android had incredibly fine-grained permission controls that was stripped out... can't have users blocking inter-app marketing key coordination after all.
- b00ty4breakfast 8mo agoThe ad industry underwrites the consumer tech market. That's why you can buy a SmartTV for like 100 bucks (or whatever, I haven't bought a tv in like 10 years knock-on-wood).
- dietr1ch 8mo agoMy plan to buy a TV is to get one that can be kept offline, or one that can be made able to stay offline through flashing or dismantling into its very core elements. Dismantling it would probably ensure it's ugly af, but maybe if you try to go for one of those TV-in-a-frame things it might not look hideous.
- giancarlostoro 8mo agoEvery smart TV I own can be kept offline; I just don't put it online ever. The issue is the software bloat makes turning them on unnecessarily slower.
- stvltvs 8mo agoI don't trust that smart TVs won't use my neighbor's open Wifi or a mobile network to phone home.
- giancarlostoro 8mo agoTime to make a wiki... How to open up your TV and yank out the wifi antenna out of it...
- deltoidmaximus 8mo agoNot sure how common it is now, but based on repair manuals my TV's wifi is provided by a standard m.2 wifi module and can be trivially removed. That wouldn't stop them from changing the TV's OS to nag or otherwise disable itself afterwards but the hardware change is about as trivial as it could be. Now why the disable wifi option isn't available on the TV when it appears in the user manual is another matter...
- _aavaa_ 8mo agoThis isn’t even a hypothetical. On most phone there’s no toggle to completely block an app’s internet access (only its data usage).
- tamimio 8mo agoWho said it’s about children?! It’s about mass surveillance and building the proper infrastructure using your tax money, both digitally and legally to expand it later with ease. They start usually in a “test bed” states (like Arizona) or countries (like Australia) and evaluate, before fully implementing it.
- gjsman-1000 8mo ago> Require browsers to respect the device's policy for site allow/blocklist But then HN would still riot, because you would need to require all apps to be approved by a central authority (no unauthorized browsers) OR you need to lock down browser engines to those that respect the list somehow (maybe by killing JIT, limiting network connections). I've learned long ago, as have politicians, there is zero solution that makes tech people happy... so move forward anyway, they'll always complain, you'll always complain, there is no tolerable solution but the status quo, which is also untenable.
- iamnothere 8mo agoFunny that you understand what the problem would be, then you still insist that the authoritarian approach is the correct one. I’m sure people like you would gladly goose step into a 100% locked down surveillance hellscape, but the rest of us will keep working to ensure that this future never happens.
- advisedwang 8mo ago> But then HN would still riot, because you would need to require all apps to be approved by a central authority (no unauthorized browsers) OR you need to lock down browser engines to those that respect the list somehow (maybe by killing JIT, limiting network connections). I don't think you need to do that. You can pass a law without creating a technical mechanism that automatically enforces the law. The law doesn't even need to be perfect. So what if you can still patch a browser yourself. Kids can steal cigarettes but laws against selling cigarettes to kids are still broadly effective. So what if its technically possible for a vendor to ship a violating browser. Go after violaters with the legal system, not with the OS. So what if there's a foreign vendor with a violating browser out of the reach of the law. You'd still have made the ecosystem vastly better even if there's gaps and loopholes.
- raw_anon_1111 8mo agoRight, I assure you that no kid who wants to smoke weed or cigarette have any trouble finding it and isn’t saying “I was going to smoke weed/cigarettes but since it’s illegal, I guess I won’t”. See also in the 1980s Nancy Reagan: “Don’t sniff glue to get high”, Kids: “You can sniff glue and get high!”
- ipsi 8mo agoThe biggest issue is, of course, (4) - how do you plan on enforcing that for sites that don't run out of your country of residence? Implicitly restrict access to only those sites in said country?
- thewebguyd 8mo agoYou don't enforce that, the owner (or the owner's parents, etc) of the device set that policy. MDMs can all already do this, there just needs to be a more user-friendly/consumer focused MDM to allow parents to control their kids devices. Just have it warn "Out of country sites may not follow your device policy, do you want to block them (Y/n)?"
- raw_anon_1111 8mo agoIt’s called “Parental Controls” you don’t need an MDM to do it.
- traverseda 8mo agoSame way the US enforces any internet foreign policy. Make the credit card companies cut them off,make advertisers cut them off. US controls most of the ways they could make money.
- Palmik 8mo agoThat issue exists with the current proposal as well or any proposal that leaves the enforcement on the website. I think in addition to what OP said, the browser/device should let you set hard domain-level filters which are enforced by the browser/device. This will not be ideal for applications / sites with mixed content, but gives the parent / guardian more control.
- thewebguyd 8mo agoIt's not implemented like that because the true goal of these laws has nothing to do with protecting children or age verification, and instead have everything to do with completely eliminating anonymity/pseudo-anonymity online. They want to ID everyone, and have all user generated content attributed to a known, identified individual.
- ericmay 8mo agoI think it's mostly easy to identify anyone if you actually want to - if you buy anything online you are 100% identifiable for example. Given the pros/cons in context, I think I'm in favor of it for social media, at least. I'd actually argue you would want to go further and you should have your full address, employer, and more available online. LinkedIn is a cesspool of awful salespeople, but you know what it's not? A massive Russian/Chinese/Maga disinformation site. Maybe you should think twice before saying something online you wouldn't say while standing in front of your house or at work. Anonymity on social media has brought a lot of problems and I'm not sure what the benefits are. Some point to a small percentage of folks who would be "outed" but, given that the alternative seems to be an emerging dystopia of bots, malicious actors, propaganda, and more, maybe actual transparency is better even taking into account potential harmful effects. I'm open-minded on this and see pros/cons either way. Though I think if you find yourself worried about this stuff you can just delete your accounts and move on with your life. Trust me you aren't missing out on anything.
- cosiiine 8mo ago"Anonymity on social media has brought a lot of problems and I'm not sure what the benefits are" Anonymity is a shield against public lynching for communities that are targeted by hate groups such as LGBTQ+ (one example, there are plenty).
- ericmay 8mo agoBut that is happening today with anonymity, but then we have all the negative stuff too.
- root_axis 8mo agoI think it's a great proposal if we add a slight alteration. Rather than requiring parents to maintain block/allow lists, the OS should allow the parent to lock in a birth-date, and that birth-date is used by the system to generate a user-age header, from there, websites can be legally required to respect the header and maintain whatever restrictions correspond to the applicable laws. This gives sites the ability to dynamically adapt to users, changing features and laws, as well as remove the burden from the parents of having to determine which sites are safe and not.
- raw_anon_1111 8mo agoSo let me tell you a story. There are plenty of states including the one I live in where you are required to verify your age to visit porn sites. If you add up all of the sites that are not hosted in the US and combine them with all of the sites that you can get around the age verification just by using a VPN, would you be surprised if I told you that the total is 100% with most just ignoring the law?
- giancarlostoro 8mo agoThis sounds more like the most reasonable solution. Part of me has wondered if there could be a PAC that focuses on pushing for issues that "both sides" can agree on to politicians from both sides. The big thing is it has to be problems both sides agree are problems, and both sides agree on the solutions. The only problem I see is that there's an insane amount of contrarianism from both sides. I have seen both sides of the political aisle flip flop on issues because one side chose one solution this time around.
- advisedwang 8mo agoI'd really like to steer away from age entirely. This requires that we have universal rules about what content is appropriate for what age, which I don't think is necessary. For kids, why not let parents decide. And why not also use this infrastructure for adults. NSFW buttons are so common that it's clearly something that adults want too.
- ElectroBuffoon 8mo agoWe already have the tech, in multiple forms. First, tagging: ASACP/RTA https://en.wikipedia.org/wiki/Association_of_Sites_Advocating_Child_Protection https://en.wikipedia.org/wiki/Association_of_Sites_Advocatin... PICS https://en.wikipedia.org/wiki/Platform_for_Internet_Content_Selection https://en.wikipedia.org/wiki/Platform_for_Internet_Content_... POWDER https://en.wikipedia.org/wiki/Protocol_for_Web_Description_Resources https://en.wikipedia.org/wiki/Protocol_for_Web_Description_R... Second, all ISPs could offer in their basic service something like DNS4EU modes, just like they offered email and web space decades ago (optional, nobody was forced to use them). DNS4EU https://en.wikipedia.org/wiki/DNS4EU#Public_resolver https://en.wikipedia.org/wiki/DNS4EU#Public_resolver Parents would only need to configure the account to "child". Laws could force companies to properly tag their pages and sites. And privacy would be preserved. Instead we have to keep on fighting the Crypto Wars. The childs are just a decoy, the target is destroying basic rights. Clipper chip war, eg. https://en.wikipedia.org/wiki/Clipper_chip#Backlash https://en.wikipedia.org/wiki/Clipper_chip#Backlash
- raw_anon_1111 8mo agoParental controls have been built into Apple devices forever. Is that not the case for Android and Windows?
- mindslight 8mo agoYou've still got it a bit backwards. Websites should be the ones publishing content suitability headers. Those headers are then legally-significant assertions about the content on the site - the type of content, age/moderation policies, etc. Browsers then implement the device's configured policy based on what headers the site returns. This requires locked down computing on the end device, but all of these proposals inherently do - otherwise a kid can always just install whatever software that sidesteps the restrictions, right? And leaving the responsibility on the device owners/makers only motivates secure boot, which is already pervasive on the most relevant devices - phones and tablets. Your proposal puts liability directly onto websites themselves, regardless of the end user/device. This would push websites into demanding remote attestation, which is at the early days of being pushed (safetynet, wei, etc), and is the thing that is really primed to destroy general purpose computing. You know all those "verifying your device" followed by endless CAPTCHAs that are everywhere these days? Imagine that, on every site, and no way to get around it besides installing a genuine copy of either Windows 2028 or macOS 28 Pyongyang.
- advisedwang 8mo agoThat's a great solution
- notatoad 8mo agoi'm surprised to see this suggestion highly upvoted, because this is the solution that usually makes hacker news the angriest. in reality this cannot be just a simple plain text header. that's way too easily forged and will not satisfy any of the parties pushing for age verification. the "device verifies your age" model means hardware attestation, so the source of that age verification can sign a cryptographically secure promise that the device software has not been modified in a way that would allow this header to be forged. the app stores might be a less than ideal place to implement age verification, but it lets regulators sidestep all the messy issues around a distinction between device owner and device user.
- bluebarbet 8mo agoPunctuation would make your ideas easier to understand.
- advisedwang 8mo agoI'm advocating for services being made to respect what the device owners decide, not that devices be made to request what the services decide. Of course, you are probably correct about the political infeasability of what I want, and are correct that this can get twisted into the exact opposite of what a just law would do.