34 ms·
The Age Verification Trap: Verifying age undermines everyone's data protection
- DeathArrow 8mo agoI wonder how much time we have before being asked to enter the government issued ID in a card reader so websites can read age and biometric data from the chip.
- brewcejener 7mo ago[dead]
- RockRobotRock 8mo agoHere is an example of the problem with inference-based verification: https://streamable.com/3tgc14 https://streamable.com/3tgc14
- ck2 8mo agoif you are paying for internet access you have to be over 18, no? and if you have internet access without paying, that means someone else is legally responsible for your access "problem solved" ?
- malfist 8mo agoFamously children can only access internet from wifi paid for by their parents. I'm not for these draconian age verification nonsense, but this isn't a valid argument.
- bondarchuk 8mo agoIt is a valid alternative avenue towards a legal implementation of "child safeguarding" IMO. Someone pays for the internet, that person is responsible for what minors do on their connection. If they have trouble doing that we can use normal societal mechanisms like idk social services, education, and government messaging. This is the way it works with e.g. alcohol and cigarettes, most places. Famously kids can just get a beer from a random fridge and chug it, but someone 16/18/21+ will be responsible and everyone seems mostly fine with this.
- nazgulsenpai 8mo agoIf protecting children were the actual intended outcome, this would have been the logical way to do it. Since it isn't what they're actually doing, instead using personally identifiable information to establish your age, we can only assume it's an attempt to deanonymize the internet.
- alt227 8mo agoThis will never work. I regularly talk to other parents at the school gates who have no idea that permissions on mobiles even exist, let alone that they can choose what they let each app have access to. The general public people just dont care.
- bondarchuk 8mo agoYes, it's hard work to build a society where people behave responsibly and in their best interests. But I'd prefer we actually put in the effort rather than go for the easy authoritarian option out of basically laziness and contempt for your fellow man. (fwiw I regularly talk to parents who are quite aware of various parental controls and use them effectively, combined with talking to their kids and just general good parenting practices)
- alt227 7mo agoYou might prefer to put in the effort, but the majority of the population arent willing to. So we must make a system which protects the naive, instead of educating everybody properly.
- moritonal 8mo agoThis is the answer. If you provide internet access to someone, you're responsible for it. It's a generally established law from a Torrenting PoV, so isn't it equally applicable to downloading content unsuitable for children. Sure it'll destroy offering free wifi, but that always was tricky from a legal PoV around responsibilities.
- daveoc64 8mo ago> if you are paying for internet access you have to be over 18, no? No, that's not the case.
- john_strinlai 8mo agoevery contract by every ISP i have ever signed has required me to be over the age of 18 to enter the contract.
- daveoc64 8mo agoIn many countries, it's possible to get a prepaid SIM with data access - without any ID or age requirement whatsoever.
- john_strinlai 8mo agoah, fair, but with an easy enough fix. make data-enabled SIM cards be 18+ (or whatever age). show ID to the store clerk at purchase time, just like if you were buying smokes/alcohol.
- bennyp101 8mo agoAnd then how does public wifi work? Stand outside a Weatherspoons, or just walk down a highstreet with free internet, back to square one
- john_strinlai 8mo agoseems dead simple to me: if you host public wifi, you are responsible for the people that use it. easy! just like you already are responsible for what happens on your free public network (torrenting, hacking, CSAM, etc.) in most jurisdictions (for what its worth, i think age verification is dumb. but it looks like we're getting it one way or the other)
- gpderetta 8mo agoIdeally the law would require websites (and apps) to provide some signed age requirement token to the client (plus possibly classification) instead of the reverse. Similarly OS and web clients should be required to provide locked down modes where the maxium age and/or classification could be selected. As a parent I would the be able to setup my child device however I wish without loss of privacy. Is it bypassable by a sufficiently determined child? Yes, but so it is the current age verification nonsense.
- sidewndr46 8mo agounless your kid never goes to public school that isn't true
- john_strinlai 8mo ago[dead]
- edgyquant 8mo agoEverything is a trade off in the world. I think that people who are anti-id ignore this but for me personally it’s harder and harder to accept the trade offs of an internet without id. AI has only accelerated this, I don’t want to live in a world where the average person unknowingly interacts with bots more than other individuals and where black market actors can sway public opinion with armies of bots. I think most people are aligned here, and that an internet without identification is inevitable whether we like it or not.
- zenbowman 8mo ago100% correct. At this point the harms to children from social media use are very well documented. Like everything else in society, there are tradeoffs here, I'm much more concerned with the damage done to children's developing brains than I am to violations of data privacy, so I'm okay with age verification, however draconian it may be.
- meowface 8mo agoWe need to destroy privacy and anonymity online for the noble goal of the government banning teenagers from looking at Twitter and Instagram? If it's a concern, parents can prevent or limit their children's use. If all this were being done to prevent consistent successful terrorist attacks in the US with tens of thousands of annual casualties, I'd say okay maybe there is an unavoidable trade-off that must be made here, but this is so absurd.
- edgyquant 8mo agoIt isn’t just about teenagers though I think I outlined that? We need to make sure people online are real people and yes we should prevent kids from being exposed to algorithms designed to addict then.
- meowface 8mo agoAdults are nearly as susceptible to such addiction. If this is the goal then the actual legislation should be to prohibit social media companies from doing it to anyone. (I think this would be government overreach and a possible first amendment violation, though. I say this as a center-left person who deeply hates what Musk has done to Twitter. I would even describe myself as an anti-free speech person; I just respect the nation's laws and the principle that the state should not be able to imprison you just for speech.)
- notTooFarGone 8mo ago>Some observers present privacy-preserving age proofs involving a third party, such as the government, as a solution, but they inherit the same structural flaw: many users who are legally old enough to use a platform do not have government ID. So there is absolutely no way to change that and give out IDs from the age of 14? You can already get an ID for children in Germany https://www.germany.info/us-de/service/reisepass-und-personalausweis/personalausweis-kinder-1216042 https://www.germany.info/us-de/service/reisepass-und-persona... This is a problem that has to be solved by the government and not by private tech companies. This is a lazy cop out to say "we have tried nothing and we are all out of ideas"
- logifail 8mo ago> This is a problem [..] (This is a genuine question) please could you describe the underlying problem that age verification is attempting to solve?
- crazypyro 8mo agoI don't think that's what the original comment was discussing at all... If governments want to require private companies to verify ages, those same governments need to provide accessible ways for their citizens to get verification documents, starting from the same age that is required.
- notTooFarGone 8mo agoNot my point in the comment but my personal opinion: To regulate access to addicting material. This is done in the physical world - why should digital be lawless when it applies to the same human behaviors? I've been addicted to a lot of digital media parts in harmful ways and I had the luck and support to grow out of most of it. A lot of people are not that lucky.
- deleted 8mo ago[deleted]
- meowface 8mo agoWhat problem? I don't think internet websites and apps actually need to know the face, age, or name of their users if their users don't want to provide that information. With exceptions for things like gambling websites.
- CrzyLngPwd 8mo agoIt's just another way to surveil the population and won't cause any real problems for anyone who can work around it.
- 2OEH8eoCRo0 8mo ago[flagged]
- cess11 8mo agoMy main takeaway from this is that politicians seem to have given up on making "social media" less harmful by regulating it, and instead focus on gatekeeping access, with the added perk of supplying security services and ad tyrants with yet another data pump.
- infotainment 8mo agoDevice based attestation seems like the way to go largely; it doesn't solve the problem, but it's good enough that it would cover most cases.
- alt227 8mo agoNot really. It just pushes the responsibility onto parents, who already have no idea how security works or what their kids are doing on their phones.
- deleted 8mo ago[deleted]
- condiment 8mo agoWe are missing accessible cryptographic infrastructure for human identity verification. For age verification specifically, the only information that services need proof of is that the users age is above a certain threshold. i.e. that the user is 14 years or older. But in order to make this determination, we see services asking for government ID (which many 14-year-olds do not have), or for invasive face scans. These methods provide far more data than necessary. What the service needs to "prove" in this case is three things: 1. that the user meets the age predicate 2. that the identity used to meet the age predicate is validated by some authority 3. that the identity is not being reused across many accounts All the technologies exist for this, we just haven't put them together usefully. Zero knowledge proofs, like Groth16 or STARKs allow for statements about data to be validated externally without revealing the data itself. These are difficult for engineers to use, let alone consumers. Big opportunity for someone to build an authority here.
- egorfine 8mo agoYou are missing the point. They don't care whether you are 14 or not. They want your biometrics and identification. "Think of the children" is just a pretense.
- yladiz 8mo agoIn general, any government already has your information, and it's naive to think that they don't; if you pay taxes, have ever had a passport, etc. they already have all identifying information that they could need. For services, or for the government knowing what you do (which services you visit), then a zero-knowledge proof would work in this case.
- IanCal 8mo agoThe companies don’t, and th government already has your government id.
- john_strinlai 8mo ago>We are missing accessible cryptographic infrastructure for human identity verification. like most proposed solutions, this just seems overcomplicated. we don't need "accessible cryptographic infrastructure for human identity". society has had age-restricted products forever. just piggy-back on that infrastructure. 1) government makes a database of valid "over 18" unique identifiers (UUIDs) 2) government provides tokens with a unique identifier on it to various stores that already sell age-restricted products (e.g. gas stations, liquor stores) 3) people buy a token from the store, only having to show their ID to the store clerk that they already show their ID to for smokes (no peter thiel required) 4) website accepts the token and queries the government database and sees "yep, over 18" easy. all the laws are in place already. all the infrastructure is in place. no need for fancy zero-knowledge proofs or on-device whatevers.
- bondarchuk 8mo agoIt's kind of weird to me how every article on this topic here has people rushing to comment within a couple minutes with some generic "yes I too support ID checks for internet use!". Has the vibe really shifted so much among tech-literate people?
- bgro 8mo agoIt’s bots pushing another false narrative. You’ll notice this in anything around politics or intelligence the past 10+ years, with big booms around 2016 and 2024 “for some reason”
- luke727 8mo agoNo. There are significant numbers of real people who genuinely support this type of thing. Dismissing it as "bots" or a "false narrative" leads to complacency that allows this stuff to pass unchallenged.
- vaylian 8mo agoThe problem is: The people who typically support this type of thing are either technically illiterate and they support it, because it sounds good. Or they are promoting these laws because they actually want more surveillance and control. It's not about protecting children. I still haven't read any truly compelling argument, why this type of surveillance is actually effective and proportionate.
- deleted 8mo ago[deleted]
- yogurt-male 8mo agoCould be astroturfing
- iamnothere 8mo agoAlthough there is some organic support, there is a lot of coordinated astroturfing. It’s apparent if you watch the discussions across platforms, there are obvious shared talking points that come in waves. Governments (and a few companies) really want this.
- enjoykaz 8mo agoMost of this debate makes more sense if the actual goal is liability reduction, not child safety. If it were genuinely about protecting kids, you'd regulate infinite scroll and algorithmic engagement optimization, not who can log in.
- malfist 8mo agoIf the US really cared about child safety they'd go after people in the epstien files.
- pembrook 8mo agoAs we can see from this user who has fallen ill with Epstein Brain, the real victims of social media algorithms are actually adults. He is currently prepping to overthrow his local Pizzeria while the rest of us argue as if social media even exists anymore (it doesn't, it's just algorithmic TV now).
- kneel25 8mo agoPretty sure they’re doing both of those things but it takes a long time for the regulation to reach the final stage
- publicdebates 8mo agoIsn't this the same debate as airports post 9/11, whether you can have both privacy and security? Seems conclusive, no.
- armchairhacker 8mo agoAge verification is very hard, because parents will give their children their unlocked account, and children will steal their parents' unlocked account. If that's criminalized (like alcohol), it will happen too often to prosecute (much more frequently than alcohol, which is rarely prosecuted anyways). I don't see a solution that isn't a fundamental culture shift. If there's a fundamental culture shift, there's an easy way to prevent children from using the internet: - Don't give them an unlocked device until they're adults - "Locked" devices and accounts have a whitelist of data and websites verified by some organization to be age-appropriate (this may include sites that allow uploads and even subdomains, as long as they're checked on upload) The only legal change necessary is to prevent selling unlocked devices without ID. Parents would take their devices from children and form locked software and whitelisting organizations.
- Buttons840 8mo agoAnd we need a standard where websites can self-rate their own content. Then locked devices can just block all content that isn't rated "G" or whatever.
- armchairhacker 8mo agoI imagine there would be a set of filters, including some on by default that most adults keep for themselves. For example, most people don't want to see gore. More would be OK with sexual content, even more would be OK with swear words, ...
- 9dev 8mo agoWrong incentive. If you don’t give a shit about exposing children to snuff or porn, but do give a shit about page views and ad revenue, you obviously don’t rate your content or rate it as G to increase that revenue.
- everdrive 8mo agoCompletely agree. The internet works differently than how people want it to, and filtering services are notoriously easy to bypass. Even if these age-verification laws passed with resounding scope and support, what would stop anyone from merely hosting porn in Romania or some country that didn't care about US age-verification laws. The leads to run down would be legion. I think you could seriously degrade the porn industry (which I wouldn't necessarily mind) but it would be more or less impossible to prevent unauthorized internet users from accessing pornography. And of course that's the say nothing of the blast radius that would come with age-verification becoming entrenched on the internet.
- deleted 8mo ago[deleted]
- Tr3nton 8mo ago[dead]
- kseniamorph 8mo ago> "Social media is going the way of alcohol, gambling, and other social sins: societies are deciding it’s no longer kids’ stuff." Oh, remember those good old times when alcohol was kids' stuff.......
- Noaidi 8mo agoIn Italy it is common for 13 and 14 year olds to have a glass of wine with dinner. The sin is not drinking, it is gluttony.
- agentultra 8mo agoThere are alternatives to ID verification if the goal is protecting children. You could, for example, make it illegal to target children with targeted advertising campaigns and addictive content. Then throw the executives who authorized such programs in jail. Punish the people causing the harm.
- varenc 8mo agoIf targeting children with advertising got corporate execs thrown in jail, wouldn't the companies just roll out age verification for users like they do now? How would this rule change their behavior? They have to know who the children are to not target them. Stronger punishment creates more of an incentive to age verify. Which is basically why it's happening now.
- barbazoo 8mo agoAt least then it wouldn't be the government requiring it, is what people may think I imagine.
- b40d-48b2-979e 8mo agoThe problem is private companies being extensions of what the government wants to do, like all of the surveillance tech in the US right now basically eviscerating the fourth amendment since they willingly hand over their data to the government without even a court order in many cases.
- cloverich 8mo ago> They have to know who the children are to not target them. There is a difference between identifying specific children, and running programs that target children more generally; and / or having research that shows how your product harms children, and failing to do anything to stop it. We can tackle both of those issues without requiring age verification. We're headed down the path of age verification because we know now that not only is social media harmful, it's especially harmful to kids, and has been specifically targeted to them. Those are things that can be fixed, regardless of how you feel about age verification. Its not different than tobacco being not allowed to create advertisements for kids; its the same type of people doing the same types of things in the end.
- TimPC 8mo agoBig tech likes this because there are a lot more face recognition technologies in the wild in real life and being able to connect all real life data to online data is quite valuable. It's also quite possibly the largest training set ever for face recognition if ids are stored and given how ids and images are sold across many companies it seems very high probability that some company will retain the data rather than delete after use.
- iririririr 8mo agoChina (and US via latin american countries and it's own poor people ...via benefit programs access via id.gov) is testing both biometrics and device id to evaluate pros and cons, and to merge data, when it come to autocratic control. In china there are places to scan you device and get coupons. usually at elevators in residential buildings so they can track also if you're arriving or leaving easily. In the US every store tracks and report to ad networks your Bluetooth ids. and we know what happens to ad networks. US now requires cars to report data, which was optional before (e.g. onstar) and china joined on this since the ev boom. the public id space is booming.
- drnick1 8mo ago> US now requires cars to report data, which was optional before (e.g. onstar) and china joined on this since the ev boom. This isn't true, there is no federal requirement for a cellular modem in cars. Most modern cars have one, but nothing prevents you from disabling or removing it. I certainly would not tolerate such a "bug" in by car. > In the US every store tracks and report to ad networks your Bluetooth ids. This also isn't true, modern phones randomize Bluetooth identifiers. I personally disable Bluetooth completely.
- iririririr 8mo agoread the connected vehicle laws. the intent was to forbid Chinese components. the actual effect is that even allowing to connect your phone will require full certification, at which point the manufacturer is financially motivated to not offer options without the telemetry they can sell to equifax et al (just like happened with smart tvs). So, yes, in practice all US cars will have radios, unless you specifically order a custom model. and yeah, your phone gives all the deniability and randon ids, etc. but if you allow apps to access location it's game over. also, just go see that google sells one option where you pay by people who saw you ad physically entered a store. (ps: sadly, I implemented the DSP side of this)
- DeathArrow 8mo ago30 years of internet were possible with relative freedom, without spying and surveillance. All of the sudden it's not possible. Governments recycle "Think of the children" mantra and they are again after terrorists and bad guys.
- xinayder 8mo agoMandatory age check is not going to reduce the number of criminals online. Period. We should focus on teaching parents how to educate their children properly, and teach children how to safely browse the internet and how to avoid common scams and pitfalls. I played Roblox when I was a teenager and all the time my aunt told me to be careful of who I talked to online, as they could be a pedo. Even though there wasn't a constant monitoring from my parents or family, her words were repeated many times that I actually thought 5 times before sharing any kind of personal information online, back then.
- iso1631 8mo agoHelping parents would be useful rather than telling them to "just do it". The pain in trying to set up fortnite and minecraft online as parents is unsummounted, involving creating half a dozen accounts with different companies just to get some form of control. Far easier to just give them an adult account. The process to create a child account should be seamless and no harder than creating an adult account.
- Attrecomet 8mo ago>Governments recycle "Think of the children" mantra and they are again after terrorists and bad guys. nope, they are going after dissenters, not bad guys. It's how it always ends up.
- jonstaab 8mo agoWhy is no one talking about using zero knowledge proofs for solving this? Instead of every platform verifying all its users itself (and storing PII on its own servers), a small number of providers could expose an API which provides proof of verification. I'm not sure if some kind of machine vision algorithm could be used in combination with zero-knowledge technology to prevent even that party from storing original documents, but I don't see why not. The companies implementing these measures really seem to be just phoning it in from a privacy perspective.
- thewebguyd 8mo agoPeople are talking about it, at least here anyway. The reason you don’t see it in policy discussion from the officials pushing these laws is because removal of anonymity is the point. It’s nit about protecting kids, it never was. It’s about surveillance and a chilling effect on speech.
- tzs 8mo agoYou do see it in policy discussions from officials in the EU. You probably don't see it in policy discussions in the US because the groups that should be telling US officials how to do age verification without giving up anonymity are not doing so.
- quotemstr 8mo agoTechnologists engage in an understandable, but ultimately harmful behavior: when they don't want outcome X, they deny that the technology T(X) works. Consider key escrow, DRM, and durable watermarking alongside age verification. They've all been called cryptographically impossible, but they're not. It's just socially obligatory to pretend they can't be done. And what happens when you create an environment in which the best are under a social taboo against working on certain technologies? Do you think that these technologies stop existing? LOL. Of course these technologies keep existing, and you end up with the worst, most wretched people implementing them, and we're all worse off. Concretely, few people are working on ZKPs for age verification because the hive mind of "good people" who know what ZKPs are make working on age verification social anathema.
- haunter 8mo agoThis is my problem with the Discord situation too: Big tech don't have wait for an outright government ban when they can just say that we are a teen-only site by default and everyone have to verify if they are over 18 or not. This age verification will affect everyone no matter what.
- DeathArrow 8mo agoIn most countries is illegal for small children to drive or to use fire arms. And it's their parents job to not let them to. Instead of requiring IDs, we should let parents manage what their children do online.
- Cthulhu_ 8mo ago> And the only way to prove that you checked is to keep the data indefinitely. This is a false premise already; the company can check the age (or have a third party like iDIN [0] do it), then set a marker "this person is 18+" and "we verified it using this method at this date". That should be enough. [0] https://www.idin.nl/en/ https://www.idin.nl/en/
- enraged_camel 8mo agoNope, as the article notes, it is actually almost never enough because it does not stand up to legal scrutiny. And for good reason: there's no way to conclusively prove that the platform actually verified the user's age, as opposed to simply saying they did, before letting them in.
- Attrecomet 8mo agoDoesn't matter, I've already had to provably identify myself, the information is a) out there b) will be used and stored, and c) will be abused and there is nothing I or the few (in terms of power) well-meaning government and corporate actors can do to change that.
- reorder9695 8mo agoAnd how do they prove to me they (and no 3rd party providers) aren't actually storing the data? I simply don't trust companies telling me they won't store something, so to me the only acceptable option is the data to never leave my device.
- ivan_gammel 8mo agoIf third party does verification with ZKP, you only need to trust that third party. The company that requires verification will not have any data to store.
- Noaidi 8mo agoI have a problem with an open internet and allowing open access to everything the internet can offer to young children. It cannot be a friction-less experience. Allowing children to see gore and extreme porn at a young age is not healthy. And then we have all the "trading" platforms (gambling). Even though my brothers were able to get many hard drugs when I was young, around 1977, there was a lot of friction. Finding a dealer, trusting them, etc. Some bars would not card us but even then there was risk and sometimes they got caught. In NY we could buy cigarettes, no friction, and the one drug I took when I was young, addicted to them at 16, finally quitting for good at 20. I could have used some friction there. So how do we create friction? Maybe hold the parents liable? They are doing this with guns right now, big trial is just finishing and it looks like a father who gave his kid an ak47 at 13 is about to go to jail. I would like to see a state ID program when the ID is just verified by the State ID system. This way nothing needs to be sent to any private party. Sites like Discord could just get a OK signal from the state system. They could use facial recognition on the phone that would match it with the ID. Something needs to be done however. I disagree that the internet needs to be open to all at any age. You do not need an ID to walk into a library, but you need one to get into a strip club. I do not see why that should not be the same on the internet.
- bronlund 8mo agoI would argue that this has nothing to do with age verification, but everything to do with getting identifiable data on all of us.
- miss_haru 8mo agoparents: won't somebody else put some rules and safeguards in place to protect my children?
- logicchains 8mo agoMost of them probably don't even have kids of their own, they just hate social media for exposing children to conservative ideas and want to ban it to prevent that.
- fuzzfactor 8mo agoMore like fear of exposing their children to anything other than carefully curated "conservative" ideas.
- barfiure 8mo agoThe internet isn’t the same as it was when we were growing up, unfortunately. I miss the days of cruising DynamicHTML while playing on GameSpy but… yeah. It became an absolute clusterfuck and I’m not surprised they now want to enforce age restrictions. Maybe TBL is right and we need a new internet? I don’t have the answer here, but this one is too commercialized and these companies are very hawkish.
- aqme28 8mo agoIf we're going to do this at all, it should be on the device, not the website/app. Parents flag their child's device or browser as under 18, and websites/apps follow suit. Parents get the control they're looking for, while service providers don't have to verify or store IDs. I guess it's just more difficult to pressure big dogs like google/apple/mozilla for this than pornhub and discord.
- thorio 8mo agoThis sounds pretty reasonable to me. What am I missing?
- butterbomb 8mo agoIt doesn’t come with a ton of PII you can sell to data brokers.
- conception 8mo agoYeah vchip style with ratings, with a setting to hide unrated sites. A simple header. Done. Have all the browsers/os support it - easy peasy.
- causal 7mo agoI’ve wondered if a age verification gig worker app could ever be viable: have people you can meet in person to prove your age without ever uploading any PII anywhere. Then issue a private key proving you are who you say you are.
- deleted 8mo ago[deleted]
- tolmasky 8mo agoI am so surprised by the comments on this thread. I was not expecting to see so many people on Hacker News in favor of this. As is typically the case with things like this, the reasoning stems from agreeing with the goal of age verification, with little regard to whether age verification could ever actually work. It reminds me in some sense to the situation with encryption where politicians want encryption that blocks "the bad guys" while still allowing "the good guys" to sneak in if necessary. Sure, that sounds cool, it's not possible though. I suppose DRM is a better analogue here, an increasingly convoluted system that slowly takes over your entire machine just so it can pretend that you can't view video while you're viewing it. To be clear, tackling the issue of child access to the internet is a valuable goal. Unfortunately, "well what if there was a magic amulet that held the truth of the user's age and we could talk to it" is not a worthwhile path to explore. Just off the top of my head: 1. In an age of data leaks, identity theft, and phishing, we are training users to constantly present their ID, and critically for things as low stakes as facebook. It would be one thing if we were training people to show their ID JUST for filing taxes online or something (still not great, but at least conveys the sensitivity of the information they are releasing), but no, we are saying that the "correct future" is handing this information out for Farmville (and we can expect its requirement to expand over time of course). It doesn't matter if it happens at the OS level or the web page level -- they are identical as far as phishing is concerned. You spoof the UI that the OS would bring up to scan your face or ID or whatever, and everyone is trained to just grant the information, just like we're all used to just hitting "OK" and don't bother reading dialogs anymore. 2. This is a mess for the ~1 billion people on earth that don't have a government ID. This is a huge setback to populations we should be trying to get online. Now all of a sudden your usage of the internet is dependent on your country having an advanced enough system of government ID? Seems like a great way for tech companies to gain leverage over smaller third world companies by controlling their access to the internet to implementing support for their government documents. Also seems like a great way to lock open source out of serious operating system development if it now requires relationships with all the countries in the world. If you think this is "just" a problem of getting IDs into everyone's hands, remember that it a common practice to take foreign worker's passports and IDs away from them in order to hold them effectively hostage. The internet was previously a powerful outlet for working around this, and would now instead assist this practice. 3. Short of implementing HDCP-style hardware attestation (which more or less locks in the current players indefinitely), this will be trivially circumvented by the parties you're attempting to help, much like DRM was. Again, the issues that these systems are attempting to address are valid, I am not saying otherwise. These issues are also hard. The temptation to just have an oracle gate-checker is tempting, I know. But we've seen time and again that this just (at best) creates a lot of work and doesn't actually solve the problem. Look no further than cookie banners -- nothing has changed from a data collection perspective, it's just created a "cookie banner expert" industry and possibly made users more indifferent to data collection as a knee-jerk reaction to the UX decay banners have created on the internet as a whole. Let's not 10 years from now laugh about how any sufficiently motivated teenager can scan their parent's phone while they're asleep, or pay some deadbeat 18 year-old to use their ID, and bypass any verification system, while simulateneously furthering the stranglehold large corporations have over the internet.
- lightningspirit 8mo agoIf there's only a centralized system that uses digital IDs to hand off providers only a "yay" or "nay"...
- anon_shill 8mo agoFrom the second paragraph: > And the only way to prove that you checked is to keep the data indefinitely. This is not true and made me immediately stop reading. If a social media app uses a third party vendor to do facial/ID age estimation, the vendor can (and in many cases does) only send an estimated age range back to the caller. Some of the more privacy invasive KYC vendors like Persona persist and optionally pass back entire government IDs, but there are other age verifiers (k-ID, PRIVO, among others) who don't. Regulators are happy with apps using these less invasive ones and making a best effort based on an estimated age, and that doesn't require storing any additional PII. We really need to deconflate age verification from KYC to have productive conversations about this stuff. You can do one thing without doing the other.
- 0x000xca0xfe 8mo agoIf you don't keep and cross-reference documents it is really easy to circumvent, e.g. by kids asking their older siblings to sign them up. I don't think a bulletproof age verification system can be implemented on the server side without serious privacy implications. It would be quite easy to build it on the client side (child mode) but the ones pushing for these systems (usually politicians) don't seem to care about that.
- anon_shill 8mo agoYep, it is easy to circumvent, and the silver lining of all of this is that regulators don't care. They care that these companies made an effort in guessing.
- deleted 8mo ago[deleted]
- boerseth 8mo agoDoes each service really need to collect this data from the user directly? They could instead have the user authorise them by e.g. OAuth2 to access their age with one of the de-facto online-identity-providers. I would be surprised if they didn't implement an API for this sometime soon, cause it would place them as the source of truth and give them unique access to that bit of user data. Seems like a chance and position they wouldn't want to lose.
- scotty79 8mo agoIf government is concerned shouldn't government just deliver auth based on birth certificate for everyone to use?
- cromka 8mo agoSomeone explain me like I'm 5: there are some solutions already in effect that are based on cryptographically generated, anonymous, one-time use tokens that allow to confirm adults's age without being tied up yo your ID. Why on earth even technically skilled people completely ignore those? Is this pure NIMBY ignorance or am missing something?
- bakugo 8mo agoBecause those solutions always have obvious flaws. If the cryptographic token is anonymous, how do you know the user verifying is the same one who generated the token? How do you know the same cryptographic key isn't verifying several accounts belonging to other people?
- cromka 8mo agoThey are one time use by definition. You can't know they are used by respectful owner, but the idea is you have to provide a new token every few weeks/months. Much like when using other services nowadays, I mean even Gmail will have you authorize every few months even if you didn't log out. Plus you fine/prosecute those who sell/misuse theirs. Just like you prosecute adults who buy kids alcohol or other substances. Obvious flaws are OK. I absolutely hate the Nirvana fallacy that you people think is acceptable here, while hundreds of millions of kids suffer from serious developmental issues, as reported left and right by all kinds of organizations and governments themselves.
- akersten 8mo agoIn my experience the people who want "privacy preserving age verification" are the same people who want "encryption backdoors but only for the good guys." Shockingly the technically minded among them do seem to recognize the impossibility of the latter, without applying the same chain of thought to the former.
- Seattle3503 8mo agoThey are fundementally different problems. It is already the governments job to maintain a record of their citizens and basic demographic information like age. Private actors are already offering verification as a paid service. They are accumulating vast troves of private date to offer the service.
- fny 8mo agoIsn't it a simpler solution to create some protocol for a browser or device announce an age restricted user is present and then have parents lock down devices as they see fit? Aside from the privacy concerns, all this age verification tech seems incredibly complicated and expensive.
- TZubiri 8mo agoI think this solution exists (e.g. android parental lock, but also ISP routers). But parents and industry have failed to do so on a greater scale. So legislation is going for a more affirmative action that doesn't require parental consent or collaboration. A service provider of adult content now cannot serve a child, regardless of the involvement or lack thereof of a parent.
- TZubiri 8mo ago>"None of this is an argument against protecting children online. It is an argument against pretending there is no tradeoff" Tradeoff acknowledged, and this runs both sides, there's hundreds of risks that these policies are addressing. To mention a specific one, I was exposed to pornography online at age 9 which is obviously an issue, the incumbent system allowed this to happen and will continue to do so. So to what tradeoffs in policy do detractors of age verification think are so terrible that it's more important than avoiding, for example, allowing kids first sexual experiences to be pornography. Dystopian vibes? Is that equivalent? Or, what alternative solutions are counter-proposed to avoid these issues without age verification and vpn bans. Note 2 things before responding: 1)per the original quote, it is not valid to ignore the trade offs with arguments like "child abuse is an excuse to install civilian control by governments" 2) this was not your initiave, another group is the one making huge efforts to intervene and change the status quo, so whatever solution is counterproposed needs to be new, otherwise, as an existing solution, it was therefore ineffective. If any of those is your argument, you are not part of the conversation, you have failed to act as wardens of the internet, and whatever systems you control will be slowly removed from you by authorities and technical professionals that follow the regulations. Whatever crumbs you are left as an admin, will be relegated to increasingly niche crypto communities where you will be pooled with dissidents and criminals of types you will need to either ignore or pretend are ok. You will create a new Tor, a Gab, a Conservapedia, a HackerForums, and you will be hunted by the obvious and inequivocal right side of the law. Your enemy list will grow bigger and bigger, the State? Money? The law? God? The notion of right and wrong which is like totally subjective anyways?
- alt227 8mo ago> I was exposed to pornography online at age 9....allowing kids first sexual experiences to be pornography I was initially exposed to pornography at 8 years old, by finding a disgarded magazine in a hedge. However this was pretty soft. I was exposed to serious pornography at 10 years by finding a hidden VHS tape in the back of a drawer at a friends house and getting curious. This was hardcore German stuff with explicit violence. This has caused me to have therapy in my lifetime. This was all in the 80s by the way. Therefore anything you are mentioning happened long before the internet, and is totally possible in a completely offline world as well. So how do these new digital laws 'protect children' again?
- redog 8mo agoIt's to continue the culture of bullying and lack-of-accountability by and for the perversely rich oligarchy. For you'll need to be accounted while they do the counting.
- _slih 8mo agothe companies pushing hardest for age verification are the same ones whose business model depends on knowing exactly who you are. the child safety framing is convenient cover for a data collection problem they were already trying to solve.
- Devasta 8mo agoI can understand the need to restrict some stuff kids can see, like when I was a teen it me hours and hours to download one 2 minute porn clip from kazaa, but these days you could download a lifetime worth in one weekend. That can't be healthy. That being said nothing about these laws is about protecting children; their primary purpose is to crack down on the next Just Stop Oil or Palestine Action so for that reason should be opposed.
- simoncion 8mo ago> ...but these days you could download a lifetime worth in one weekend. Uh. I could check in the back of my parents' closet (hidden under some fabric) for at least a decade's worth of dirty magazines. It's true that that's less than a lifetime's worth of pictures and articles, but I'd say that that's effectively equivalent. > That can't be healthy. The only thing that's unhealthy is not being able to talk frankly and honestly about sex and sexuality with your peers, parents, and other important adults in your life. Well, that and never being told that sex leads to pregnancy, or how to recognize common STDs... but you're likely to get that "for free" if you're able to talk frankly and honestly about sex and sexuality.
- StopDisinfo910 8mo ago> their primary purpose is to crack down on the next Just Stop Oil or Palestine Action so for that reason should be opposed. Could you explain to me how a digital id standard involving a mechanism for zero knowledge proof of identity is supposed to help the government crack down on activists (skipping the fact you are using UK examples for a EU spec)? Take into account the reality we live in where every communication platform already requires you to provide your phone number and you can't get a phone number without providing an ID the European Union please, not some disconnected threat model.
- matthewmorgan 8mo agoThat was the goal.
- callamdelaney 8mo agoWe should just ban smartphones, it's where a great deal of the harm comes from and is harder for parents to manage. No need for children to have cameras connected to the internet whether via smartphones or computers.
- julianozen 8mo agoThere is missing a solution. Give our personal devices have the ability to verify our age and identity securely and store on device like they do our fingerprint or face data. Services that need access only verify it cryptographically. So my iPhone can confirm I’m over 21 for my DoorDash app in the same way it stores my biometric data. The challenge here is the adoption of these encryption services and whether companies can rely on devices for that for compliance without having to cut off service for those without it set up.
- snvzz 8mo agoThe solution has always been there: Assume everybody is an adult. The only reasonable way to deal with children on the Internet is to treat Internet access like access to alcohol/drugs. There is no need for children to access the Internet full stop. Internet is a network in which everything can connect to everything, and every connected machine can run clients, servers, p2p nodes and what not. Controlling every possible endpoint your child might connect to is not feasible. Shutting the entire network down because "won't somebody please think of the children" is not acceptable. And, don't let them trick you. This is the endgoal. An unprecedented level of control over the flow of information.
- Squarex 8mo agoSo you would deny children the greatest source of knowledge in the history? I have learned math and programming thanks to unlimited access to the web and would not be where I am without it.
- Almondsetat 8mo ago>I would not be where I am without it First of all, you cannot know that, since plenty of people before you learnt that stuff from libraries. >So you would deny children the greatest source of knowledge in the history? Yes, because other sources of knowledge exist and are much more appropriate for children. It is also the greatest source of despicable stuff in history. When you turn 18, have fun exploring the world wide web.
- 8mo ago
- b8 8mo agoHence why Illinois has already mame it illegal.
- djohnston 8mo ago(thats the point)
- simion314 8mo agoBig Tech refused to work together to implement a age flag that parents would setup on the children device, now we get each European and each USA state with their own special rules.
- alt227 8mo agoI like the solution Tim Burners-Lee is working on. Lets hope he has some success. https://solidproject.org/ https://solidproject.org/ https://www.theguardian.com/technology/2026/jan/29/internet-inventor-tim-berners-lee-interview-battle-soul-web https://www.theguardian.com/technology/2026/jan/29/internet-...
- JohnMakin 8mo agoWe'll try everything, it seems, other than holding parents accountable for what their children consume. In the United States, you can get in trouble if you recklessly leave around or provide alcohol/guns/cigarettes for a minor to start using, yet somehow, the same social responsibility seems thrown out the window for parents and the web. Yes, children are clever - I was one once. If you want to actually protect children and not create the surveillance state nightmare scenario we all know is going to happen (using protecting children as the guise, which is ironic, because often these systems are completely ineffective at doing so anyway) - then give parents strong monitoring and restriction tools and empower them to protect their children. They are in a much better and informed position to do so than a creepy surveillance nanny state. That is, after all, the primary responsibility of a parent to begin with.
- lenerdenator 8mo agoThe thing is, what are the parents to do beyond restricting things? You find out some creep has been talking to Junior; do you talk to your local police department, state agency, or to the feds? We've never properly acted upon reports of predators grooming children by investigating them, charging them, holding trials, and handing down sentences on any sort of large scale. There's a patchwork of LEOs that have to handle things and they have to do it right. Once the packets are sent over state lines, we have to involve the feds, and that's another layer. Previously, I would have said it's up to platforms like Discord to organize internal resources to make sure that the proper authorities received reports, because it felt like there were instances of people being reported and nothing happening on the platform's side. Now, given recent developments, I'm not sure we can count upon authorities to actually do the job.
- robomartin 8mo ago> The thing is, what are the parents to do beyond restricting things? Well, I can't speak for parents (as in all parents). I can, however, tell you what we did. When two of my kids were young we gave them iPods. The idea was to load a few fun educational applications (I had written and published around 10 at the time). Very soon they asked for Clash of Clans to play for a couple of hours on Saturdays. We said that was OK provided they stuck to that rule. Fast forward to maybe a couple of months later. After repeated warnings that they were not sticking to the plan and promises to do so, I found them playing CoC under the blankets at 11 PM, when they were supposed to be sleeping and had school the next day. I did not react and gave no indication of having witnessed that. A couple of days later I asked each of them to their room and asked them to place their top ten favorite toys on the floor. I then produced a pair of huge garbage bags and we put the toys in them, one bag for each of the kids. I also asked for their iPods. No anger, no scolding, just a conversation at a normal tone. I asked them to grab the bags and follow me. We went outside, I opened the garbage bin and told them to throw away their toys. It got emotional very quickly. I also gave them the iPods and told them to toss them into the bin. After the crying subsided I explained that trust is one of the most delicate things in the world and that this was a consequence of them attempting to deceive us by secretly playing CoC when they knew the rules. This was followed by daily talks around the dinner table to explain just how harmful and addictive this stuff could be, how it made them behave and how important it was to honor promises. Another week later I asked them to come into the garage with me and showed them that I had rescued their favorite toys from the garbage bin. The iPods were gone forever. And now there was a new rule: They could earn one toy per month by bringing top grades from school, helping around the house, keeping their rooms clean and organized and, in general, being well behaved. That was followed by ten months of absolutely perfect kids learning about earning something they cherished every month. Of course, the behavior and dedication to their school work persisted well beyond having earned their last toy. Lots of talks, going out to do things and positive feedback of course. They never got the iPods back. They never got social media accounts. They did not get smart phones until much older. To this day, now well into university, they thank me for having taken away their iPods. So, again, I don't know about parents in the aggregate, but I don't think being a good parent is difficult. You are not there to be an all-enabling friend, you are there to guide a new human through life and into adulthood. You are there to teach them everything and, as I still tell them all the time, aim for them to be better than you. https://www.youtube.com/watch?v=99j0zLuNhi8 https://www.youtube.com/watch?v=99j0zLuNhi8
- Filip_portive 8mo agoMy new comment
- yde_java 8mo ago[dead]
- 2duct 8mo agoI'm going to state that at one point I was one of the young people this kind of legislation is meaning to protect. I was exposed to pornography at too young an age and it became my only coping mechanism to the point where as an adult it cost me multiple jobs and at one point my love life. I don't think this legislation would have helped me. I found the material I did outside of social media and Facebook was not yet ubiquitous. I did not have a smartphone at the time, only a PC. I stayed off social media entirely in college. Even with nobody at all in my social sphere, it was still addicting. There are too many sites out there that won't comply and I was too technically savvy to not attempt to bypass any guardrails. The issue in my case was not one of "watching this material hurt me" in and of itself. It was having nobody to talk to about the issues causing my addiction. My parents were conservative and narcissistic and did not respect my privacy so I never talked about my addiction to them. They already punished me severely for mundane things and I did not want to be willingly subjected to more. To this day they don't realize what happened to me. The unending mental abuse caused me to turn back to pornography over and over. And I carried a level of shame and disgust so I never felt comfortable disclosing my addiction to any school counselors or therapists for decades. The stigma around sexual issues preventing people from talking about them has only grown worse in the ensuing years, unfortunately. At most this kind of policy will force teenagers off platforms like Discord which might help with being matched with strangers, but there are still other avenues for this. You cannot prevent children from viewing porn online. You cannot lock down the entire Internet. You can only be honest with your children and not blame or reproach them for the issues they have to deal with like mine did. In my opinion, given that my parents were fundamentally unsafe people to talk to, causing me to think that all people were unsafe, then the issue of pornography exposure became an issue. In my case, I do not believe there was any hope for me that additional legislation or restrictions could provide, outside of waking up to my abuse and my sex addiction as an adult decades later. Simply put, I was put into an impossible situation, I didn't have any way to deal with it as a child, and I was ultimately forsaken. In life, things like those just happen sometimes. All I can say was that those who forsook me were not the platforms, not the politicians, but the people who I needed to trust the most. I believe many parents who need to think about this issue simply won't. The debate we're having here on this tech-focused site is going to pass by them unnoticed. They're not going to seriously consider these issues and the status quo will continue. They won't talk with their children to see if everything's okay. I don't have many suggestions to offer except "find your best family," even if they aren't blood related.
- alvatar 8mo agozero knowledge cryptography solves this
- vaylian 8mo agoIs there any production ready implementation out there?
- MatteoFrigo 8mo agoZKP is integrated in Google Wallet and has been running in production for a few months. We (Google) released the ZKP library as open source last year (this is the library used in production). Announcement: https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/ https://blog.google/innovation-and-ai/technology/safety-secu... Library: https://github.com/google/longfellow-zk https://github.com/google/longfellow-zk Paper: https://eprint.iacr.org/2024/2010 https://eprint.iacr.org/2024/2010 Afterwards, folks from ISRG produced an independent implementation https://github.com/abetterinternet/zk-cred-longfellow https://github.com/abetterinternet/zk-cred-longfellow with our blessing and occasional help. I don't know if the authors would call it "production ready" yet, but it is at least code complete, fast enough, and interoperable with ours.
- vaylian 8mo agoThanks. I'll have a look.
- EmbarrassedHelp 8mo agoOnly in theory, and only if you blindly trust a third party. The implementations in practice are still massive privacy violations.
- alvatar 7mo agowhat third party do you need? The program can be opensource. The verification can be done onchain
- robinwhg 8mo agoI‘m not too knowledgeable about this, but couldn’t you just provide a government issued key to every citizen and give a service provider that key and it‘s only valid if you’re above a certain age?
- ct0 8mo agoI don't get the alcohol analogy as in most places it's 100% legal for minors to consume alcohol in the home with parental permission in the USA. In public it's a different story.
- rglover 8mo agoImagine an OIDC type solution but for parents might work here. Basically, kids can sign up for an account triggering a notification to parents. The parent either approves or rejects the sign in. Parents can revoke on demand. See kids login usage to various apps/services. Gets parental restrictions in the login flow without making it a PITA.
- rafaelero 8mo agoI have no idea where this idea that Internet is toxic to children is coming from. Is that some type of moral panic? Weren't most of you guys children/adolescents during the 2000's?
- Salgat 8mo agoAre you saying that social media isn't harmful to children?
- rafaelero 8mo agoLast time I checked there's no scientific consensus if social media causes harm at all. The best studies found null or very small effects. So yeah, I am skeptical it is harmful.
- ok123456 8mo agoThis is like rhetorically asking, "Are you saying that doom and marylin manson aren't harmful to children?" The problem with social media isn't the inherent mixing of children and technology, as if web browsers and phones have some action-at-a-distance force that undermines society; it's the 20 years or so they spent weaponizing their products into an infinite Skinner box. Duck walk Zuckerburg. This is all assuming good faith interest in "the children," which we cannot assume when what government will gain from this is a total, global surveillance state.
- arrsingh 8mo agoAge Verification is very hard to do without exposing personal information (ask me how I know). I feel it should be solved by a platform company - someone like Apple (assuming we trust apple with our personal information but seems like we already do) - and the platform (ios) should be able to simply provide a boolean response to "is this person over 18" without giving away all the personal information behind the age verification. Now the issue of which properties can "ask to verify your age" and "apple now knows what you're looking at" is still an unsolved problem, but maybe that solution can be delivered by something like a one time offline token etc. But again, this is a very hard problem to solve and I would personally like to not have companies verify age etc.
- kuon 8mo agoEven if you design the perfect system, kids will just ask parents for an unlocked account, many parents will accept, myself included. My kids have full access to the internet and I never used parental control, I talk to them. Of course, I don't want to give parenting advice, that would be presumptuous. But, my point is that a motivated kid will find a way, you have to "work" on that motivation. Many of the worst present on the internet is not age gated at all, you have millions of porn websites without even a "are you over 18" popup. There are plethora of toxic forums... Of course it's a complex problem, but the current approach sacrifice a lot of what made the internet possible and I don't like it.
- kypro 8mo ago> Many of the worst present on the internet is not age gated at all, you have millions of porn websites without even a "are you over 18" popup. There are plethora of toxic forums... This is what I find most insane about the UK's age verification law. It's literally so easy to find adult content without proving your age... You can literally just type in "naked women" into a search engine and get porn... To call it ineffective would be an understatement. Finding adult content on the web almost just as easy as it's always been. The only thing it's made harder is accessing adult content from the normie-web – you can't access porn on places like Reddit anymore, but you can access porn on 4chan and other dodgy adult sites. If the argument is "think about the kids" there are more effective ways to do it... Requiring device-level filtering for example would likely be more effective because it could just blacklist domains with hosting adult content unless unrestricted. It would also put more power in the parents hands about what is and what isn't restrict.
- donmcronald 8mo agoThe solution is education. The most well adjusted kids I've seen are told flat out about the risks they'll face and, in general, helped to understand there are break points where things get too serious for them to try to deal with on their own. I think that if you block all porn, social media, etc. all that does is create an opportunity for kids to be shifted to platforms controlled by bad actors. Adults fall victim to pig butchering schemes where they're given 100% fake investment apps that look completely real and they don't realize they're getting scammed until they try to get their money out of the system. There was a story in Canada about a guy and his daughter that thought they had $1 million in savings and it was a pig butchering scam with a fake app. Are kids today equipped to deal with that? What happens when someone tells a kid to get app XYZ because it's un-moderated, but that app is controlled by a bad actor? Imagine a Snapchat like platform promising ephemeral messaging with simple username / password on-boarding so parents don't see account creation emails, but the app is run by organized crime. I don't even know how you handle it if they manage to normalize the idea of children sending ID to random platforms. In addition to getting platform shifted and exploited, kids will be vulnerable to sending their real ID to bad actors. The whole thing seems insane to me. Spend some money on education. That's the only long-term option.
- light_hue_1 8mo agoAs a parent, I'm happy that social bans are finally a thing. But, I don't get the approach. It's not like social media starts being a positive in our life at 20. The way these companies do social media is harmful to mental health at every age. This is solving the wrong problem. The solution is to take away their levers to make the system so addictive. A nice space to keep in touch with your friends. Nothing wrong with that.
- deleted 8mo ago[deleted]
- scythe 8mo agoIt's crazy to me that we want to force age verification on every service across the Internet before we ban phones in school. I could understand being in favor of both, or neither, but implementing the policy that impacts everybody's privacy before the one that specifically applies within government-run institutions is just so disappointingly backwards it's tempting to consider conspiracy-like explanations. The advantage, I think, of age verification by private companies over cellphone bans in public schools is that cellphone bans appear as a line-item on the government balance sheet, whereas the costs of age verification are diffuse and difficult to calculate. It's actually quite common for governments to prefer imposing costs in ways that make it easier for the legislators to throw up their hands and whistle innocently about why everything just got more expensive and difficult. And the argument over age verification for merely viewing websites, which is technically difficult and invasive, muddles the waters over the question of age verification for social media profiles, where underage users are more likely to get caught and banned by simple observation. The latter system has already existed for decades -- I remember kids getting banned for admitting they were under 13 on videogame forums in the '00s all the time. It seems like technology has caused people to believe that the law has to be perfectly enforceable in order to be any good, but that isn't historically how the law has worked -- it is possible for most crimes to go unsolved and yet most criminals get caught. If we are going to preserve individual privacy and due process, we need to be willing to design imperfect systems.
- StopDisinfo910 8mo ago> It's crazy to me that we want to force age verification on every service across the Internet before we ban phones in school. France banned phones in elementary and noddles schools in 2018. It's not the only European country to have done so.
- arbirk 8mo agoI know many will disagree and that is ok. Imo we need global id based on nation states national id. I know that the US doesn't have that, but the rest of the developed world do. I don't want id on porn sites because I don't think that is necessary, but I want bot-free social media, 13+ sharing forums like reddit and I want competitive games where if you are banned you need your brothers id to try cheating again.
- Seattle3503 8mo ago> Some observers present privacy-preserving age proofs involving a third party, such as the government, as a solution, but they inherit the same structural flaw: many users who are legally old enough to use a platform do not have government ID. In countries where the minimum age for social media is lower than the age at which ID is issued, platforms face a choice between excluding lawful users and monitoring everyone. Right now, companies are making that choice quietly, after building systems and normalizing behavior that protects them from the greater legal risks. Age-restriction laws are not just about kids and screens. They are reshaping how identity, privacy, and access work on the Internet for everyone. This rebuttal to privacy preserving approaches isn't compelling. Websites can split the difference and use privacy preserving techniques when available, and fall back to other methods when the user doesn't have an ID. I'd go further and say websites should be required to prioritize privacy preserving techniques where available. There is a separate issue of improving access to government ID. I think that is important for reasons outside of age verification. Increasingly voting, banking, etc... already relies on having an ID.
- trashb 8mo agoI would like to take the discussion in the other direction. How about we offer safe spaces instead of banning the unsafe spaces for kids. Similar to how there is specific channels for children on the TV. Perhaps the government can even incentivize such channels. It would also make it easier for parents to monitor and set boundaries. Parents would only need to monitor if the tv is still tuned to disney channel or similar instead of some adult channels. Similarly this kind of method could be applied to online spaces. Ofcourse there will be some kids that will find ways around it but they will most likely be outliers.
- NoMoreNicksLeft 8mo ago>How about we offer safe spaces instead of banning the unsafe spaces for kids. Children shouldn't be associating with other children, except in small groups. Even the typical classroom count is far too large. They become the nastiest, most horrible versions of themselves when they congregate. A good 90% of the pathology of public schools can be blamed on the fact that, by definition, public schools require large numbers of children to congregate.
- deleted 8mo ago[deleted]
- antitoxic 8mo agoI work at a European identity wallet system that uses a zero knowledge proof age identification system. It derives an age attribute such as "over 18" from a passport or ID, without disclosing any other information such as the date of birth. As long as you trust the government that gave out the ID, you can trust the attribute, and anonymously verify somebodies age. I think there are many pros and cons to be said about age verification, but I think this method solves most problems this article supposes, if it is combined with other common practices in the EU such as deleting inactive accounts and such. These limitations are real, but tractable. IDs can be issued to younger teenagers, wallet infrastructure matures over time, and countries without strong identity systems primarily undermine their own age bans. Jurisdictions that accept facial estimation as sufficient verification are not taking enforcement seriously in the first place. The trap described in this article is a product of the current paradigm, not an inevitability.
- nemomarx 8mo agoThis is true, but I think it's more that those jurisdictions don't actually care about something solving this securely so much as they want face scans for other purposes?
- brunoborges 8mo agoYeah, but how to convince investors that trusting the government-issued ID is good enough? /s
- uniq7 8mo agoIn your system, can companies verify age offline, or do they need to send a token to the Government's authority to verify it (letting the Government identify and track users)? Switzerland is working on a system that does the former, but if Government really wants to identify users, they can still ask the company to provide the age verification tokens they collected, since the Government hosts a centralized database that associates people with their issued tokens.
- tgsovlerkhgsel 8mo agoAren't the companies also expected to do revocation checking, essentially creating a record of who identified where, with a fig leaf of "pseudonymity" (that is one database join away from being worthless)?
- dark-star 8mo agoI don't see why platforms would have to store the data indefinitely. Once you are verified, you just flip a bit "verified" in the database and delete all identification data. No reason to store the data indefinitely
- knallfrosch 8mo agoAll adults proof their identify multiple times per month: Every time they access digital health records, or when they use any electronic payment. Just make Google/Apple reveal part of that data (age > x years) to websites and apps. Boom, done. Privacy guarded. Easy.
- fuzzfactor 8mo ago>Every time they access digital health records, or when they use any electronic payment. This is the internet. Among those who were very familiar with it, the smartest money never started doing things like that.
- SoftTalker 8mo agoA lot of talk and no solutions. Exactly the reason we are where we are. Liquor stores, bars, strip clubs, adult bookstores, or similar businesses don't let kids in. Movie theatres don't let a 10 year old in to an R-rated movie. The tech industry ignored their social responsibility to keep kids away from adult and age-inappropriate content. Now, they are facing legal requirements to do so. Tough for them, but they could have been more proactive.
- reorder9695 8mo agoWhat's always got me about this is when I was in school I had it absolutely drilled into me that I should never expose personal information online to anyone, I completely saw the logic in that and so heavily limit the personal data I give out. Now we're just expecting people to completely go against that and give away the most personal details possible to companies who cannot prove what they are or are not doing with it just because governments have decided that's best now?
- co_king_5 8mo ago[dead]
- jama211 8mo agoThis thread is gonna be full of HN users blaming the parents for a systemic problem isn’t it? Yup.
- Galanwe 8mo agoWell there are technical solutions for this: blind signatures. I could generate my own key, have the government blind sign it upon verifying my identity, and then use my key to prove I'm an adult citizen, without anyone (even the signing government) know which key is mine. Any veryfying entity just need to know the government public key and check it signed my key.
- halls-940 8mo agoI was thinking the same thing. Why don't we just get a key from the government?
- Galanwe 8mo ago> Why don't we just get a key from the government? Because one could argue that the government could keep track of the keys they give away. That is where blind signing is interesting. The government can sign _your_ key without knowing it.
- Aurornis 8mo agoThe ID check laws are about matching an identity to a user account. If the identity check was blind it wouldn't actually be an identity check. It would be "this person has access to an adult identity". If there is truly no logging or centralization, there is no limit on how many times a single ID could be used. So all it takes is one of those adult blind signatures to be leaked online and all the kids use it to verify their accounts. It's a blind process, so there's no way to see if it's happening. Even if there was a block list, you would get older siblings doing it for all of their younger siblings' friends because there is no consequence. Or kids stealing their parents' signature and using it for all of their friends.
- Galanwe 8mo agoI don't quite get your point. The signer is blind to what it signs, but that does not mean there is no identity per se. A signed key is still unique. - You can still check that user 1 and user 2 don't use the same key. - You can still issue a challenge to the user every 10 days to make sure he has indeed access to his key and not just borrowed it. - You can still enforce TPM use of said keys, so that they cannot be extracted or distributed online, but require a physical ID card. - You can still do whatever revocation system you want for the cases when a key is stolen or lost. Really the "blind" nature of the signature changes nothing to what you would normally do with a PKI.
- arn3n 8mo agoParents are competing with multi-trillion dollar companies who have invested untold amounts of cash and resources into making their content addictive. When parents try to help their children, it's an uphill battle -- every platform that has kids on it also tends to have porn, or violence, or other things, as these platform generally have disappointingly ineffective moderation. Most parents turn to age verification because it's the only way they can think of to compete with the likes of Meta or ByteDance, but the issue is that these platforms shouldn't have this content to begin with. Platforms should be smaller -- the same site shouldn't be serving both pornography and my school district's announcement page and my friend's travel pictures. Large platforms are turning their unwillingness to moderate into legal and privacy issues, when in fact it should simply be a matter of "These platforms have adult content, and these ones don't". Then, parents can much more easily ban specific platforms and topics. Right now there's no levers to pull or adjust, and parent s have their hands tied. You can't take kids of Instagram or TikTok -- they will lose their friends. I hate the fact that the "keep up with my extended family" platform is the same as the "brainrot and addiction" one. The platforms need to be small enough that parents actually have choices on what to let in and what not to. Until either platforms are broken up via. antitrust or until the burden of moderation is on the company, we're going to keep getting privacy-infringing solutions. If you support privacy, you should support antitrust, else we're going to be seeing these same bills again and again and again until parents can effectively protect their children.
- flerchin 8mo agoThe thing that needs to be age banned, or really just banned, is algorithmic feeds with infinite scroll. Kids (and adults) need to just interact with their friends, and block all the bait.
- brainwad 8mo agoFor adults, I think a legal opt-in-only policy would work well. And require reconsent with every major algorithm change.
- Wobbles42 8mo agoThe purpose of a system is what it does. Undermining data protection and privacy is clearly the point. The fact that it's happening everywhere at the same time makes it look to me like a bunch of leaders got together and decided that online anonymity is a problem. It's not like kids having access to adult content is a new problem after all. Every western government just decided that we should do something about it at roughly the same time after decades of indifference. The "age verification" story is casus belli. This is about ID, political dissent, and fears of people being exposed to the wrong brand of propaganda.
- snerbles 8mo agoExactly. So many comments here about technical solutions are missing the underlying government/authority problem, or are actively a part of it.
- qweflkj 8mo ago> The purpose of a system is what it does. How far does it go? Are all bugs features? Shall we assume that Boeing (via MCAS) and Ford (via the Pinto) were trying to kill their passengers? There's a difference between ulterior motive and incompetent execution of expressed intention.
- user3939382 8mo agoNo, this is proven false by reducing this theory to the individual level. Anyone who has tried to design/imagine -> actually build something, be it an artist, architect, song writer, programmer, or otherwise, knows there is inevitably a gap between design and realization. No one involved in that process would at any point consider the gap to be part of its “purpose”. People do hide their intentions but that doesn’t give us a license to reduce complex system dynamics to absurdities.
- Wobbles42 8mo agoBugs get fixed when systems are iterated on. They also tend to be single results from single mistakes, not compound end results of the implementation. Design features tend to persist. The phrase/idiom "the purpose of a system is what it does" maps best to situations where a multiple decisions within a system make little sense when viewed through the lens of the stated purpose, but make perfect sense if the actual outcome is the desired one. It is an invitation to analyze a system while suspending the assumption of good faith on the part of the implementors.
- Pxtl 8mo agoAll of my kids devices are identified, at device level, as children's devices. They could've trivially exposed this as metadata to allow sites to enforce "no under 18" use. However, I'd disagree that my bigger concern for my kids isn't that they'd see a boob or a penis, but that they'd see an influencer who'd try to radicalize them to some extremist cause, and that's usually not considered 18+ content. And either way, none of that requires de-anonymizing literally everyone on the internet. I'd be more than happy to see governments provide cryptographically secure digital ID and so that sites can self-select to start requiring this digital ID to make moderation easier.
- steve_taylor 8mo agoThe problem with that is that sites/apps will retain the identifier, either to use the Digital ID for login (not just one-time age verification), because they want to retain as much information as possible for later usage or sale, or because a government told them they have to retain it so all their social media activity can be easily linked to them.
- Pxtl 7mo agoThat's what we have now, but mandatorily, and without the anti-sockpuppet protection a true ID would provide. I have conspiracy theories about the conspiracy theories about digital ID. The people who benefit the most from fake people posting are spambots, sockpuppets, disinfo peddlers, and astroturfers. And either way, I firmly believe that a site should be free allow you to log in without a digital ID... I just would like to be able to know who doesn't have one so I can know who's a real human being and who is an appendage.
- almosthere 8mo agoI think this should work like OpenID connect but with just a true/false. PS = pr0n site AV = age verification site (conforming to age-1 spec and certified) PS: Send user to AV with generated token AV: Browser arrives with POST data from PS with generated token AV: AV specific flow to verify age - may capturing images/token in a database. May be instant or take days AV: Confirms age, provides link back to original PS PS: Requests AV/status response payload: { "age": 21, "status": "final" } No other details need to be disclosed to PS. I don't know if this is already the flow, but I suspect AV is sending name, address, etc... All stuff that isn't needed if AV is a certified vendor.
- EmbarrassedHelp 8mo agoThat solution still violates user privacy. A better solution would be a simple "minor" flag that is only included on the devices of minors. No third party verification required for adults.
- almosthere 8mo agoThat works until minor-removing-flag proxys start popping up.
- nye2k 8mo agoI worked for a decade in what I would consider the highest level of our kids' privacy ever designed, at PBS KIDS. This was coming off a startup that attempted to do the same for grownups, but failed because of dirty money. Every security attempt becomes a facade or veil in time, unless it's nothing. Capture nothing, keep nothing, say nothing. Kids are smart AF and will outlearn you faster than you can think. Don't even try to capture PII ever. Watch the waves and follow their flow, make things for them to learn from but be extremely careful how you let the grownups in, and do it in pairs, never alone.
- pessimizer 8mo agoThe point is to undermine data protection; this debate is useless. It's a question about power and control, not a technical one. The people lobbying for this don't care about children, and neither are they getting big support from a constituency clamoring for this. This is an intelligence initiative, and a donor initiative from people who are in a position to control the platform (all computing and communications) after it is locked down. It's not even worth talking about online. There's too much inorganic support for the objectives of nation-states and the corporations that own them. Legislation has been advanced in Colorado demanding that all OSes verify the user's age. It will fail, but it will be repeated 100 times, in different places, smuggled attached to different legislation, the process and PR strategies refined and experimented with, versions of it passed in Australia, South Korea, maybe the UK and Europe, and eventually passed here. That means that "general purpose" computing will be eventually be lost to locked bootloaders. https://www.pcmag.com/news/colorado-lawmakers-push-for-age-verification-at-the-operating-system-level https://www.pcmag.com/news/colorado-lawmakers-push-for-age-v... [edit: I'm an idiot, they already passed it in California https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-introduces-new-age-verification-requirements-for-software-applications https://www.hunton.com/privacy-and-cybersecurity-law-blog/ca...] And it will be an entirely engineered and conscious process by people who have names. And we will babble about it endlessly online, pretending that we have some control over it, pretending that this is a technical discussion or a moral discussion, on platforms that they control, that they allow us to babble on as an escape valve. Then, one day the switch will flip, and advocacy of open bootloaders, or trading in computers that can install unattested OSes, will be treated as organized crime. All I can beg you to do is imagine how ashamed you'll be in the future when you're lying about having supported this now, or complaining that you shouldn't have "trusted them to do it the right way." Don't let dumb fairytales about Russians, Chinese, Cambridge Analytics and pedophile pornography epidemics have you fighting for your own domination. Maybe you'll be the piece of straw that slows things down just enough that current Western oligarchies collapse before they can finish. Maybe we'll get lucky. Polls and ballots show that none of this stuff has majority organic support. But polls can be manipulated, and good polls have to be publicized for people to know they're not alone, and not afraid they're misunderstanding something. If both candidates on the ballot are subverted, the question never ends up on the ballot. The article itself says nothing that hasn't been said before, and stays firmly under the premise that access to content online by under-18s is suddenly one of the most critical problems of our age, rather than a sad annoyance. What is gained by having this dumb discussion again?
- LePetitPrince 8mo ago[dead]
- mgaunard 8mo ago"Think of the children" is merely a political argument to get a law to be popular among normal people.
- Ginden 8mo ago"Age-restriction laws push platforms toward intrusive verification systems that often directly conflict with modern data-privacy law" - when you make rules contradictory, someone always violate these laws, and you can use selective persecution to "convince" companies to favor you, the incumbent politician. You don't even have to use such power, just a "joke" may be enough to send have any rational CEO licking your shoes. European proponents of "anti-big-tech action" make it pretty explicit - broad discretionary power should be given to executive branch, because otherwise "international corporations" will use "loopholes" (and these "loopholes" are, in practice, explicitly written laws used as intended).
- kylecordes 8mo ago"Verifying age undermines everyone's data protection" That's the whole point, right? A pretense to remove any remaining anonymity from communications? Governments are endlessly infested with the worst people. They look back at historical attempts at totalitarianism and think to themselves, "Let's facilitate something like that, but worse".
- radium3d 8mo agoIt's insanely dangerous to have so much data stored on so many servers that are inevitably not maintained.
- edoceo 8mo agoI'm certain there is a way to verify age without compromise of privacy or identity. I'm sure it's possible to build some oAuth like flow that could allow sites to verify both human-ness and age. The systems and corporations that gate that MUST (in the RFC sense) be separate from the systems and corporations that want the verification. Do we need laws to make this happen? What methods can be used to aid adoption? Do site operators really want to know the humanness and ages or are those just masks on adding more surveillance?
- catoc 8mo agoIt’s the same as scanning for CSAM, or encryption-backdoors “to catch criminals”. Of course we hate child abuse. Of course we hate criminals. Of course we hate social media addicting our kids. But they’re just used as emotional framing for the true underlying desire: government surveillance. (For the record: I am not into conspiracy theories; the EU has seen proposals for - imho technically impossible - “legally-breakable encryption” alone in 2020, 2022, and 2025; now we”ll also see repeated attempts at the “age verification” thing to force all adults to upload their IDs to ‘secure’ web portals)
- 1vuio0pswjnm7 8mo ago"In cases when regulators demand real enforcement rather than symbolic rules, platforms run into a basic technical problem. The only way to prove that someone is old enough to use a site is to collect personal data about who they are." These so-called "platforms" already collect data about who people are in order to facilitate online advertising and whatever else the "platform" may choose to do with it. There is no way for the user to control where that data may end up or how it may be used. The third party can use the data for any purpose and share it with anyone (or not). Whether they claim they do or don't do something with the data is besides the point, their internal actions cannot be verified and there are no enforceable restrictions in the event a user discovers what they are doing and wants to stop them (at that point it may be too late for the user anyway) "Tech" journalists and "tech bros" routinely claim these "platforms" know more about people than their own families, friends and colleagues That's not "privacy" Let's be honest. No one is achieving or maintaining internet "privacy" by using these "platforms", third party intermediaries (middlemen) with a surveillance "business model", in order to communicate over the internet On the contrary, internet "privacy" has been diminishing with each passing year that people continue to use them The so-called "platforms" have led to vast repositories of data about people that are used every day by entities who would otherwise not be legally authorised or technically capable of gathering such surveillance data. Most "platform" users are totally unaware of the possibilities. The prospect of "age verification" may be the wake up call "Age verification" could potentially make these "platforms" suck to a point that people might stop using them. For example, it might be impossible to implement without setting off users' alarm bells. In effect, it might raise more awareness of how the vast quantity of data about people these unregulated/underregulated third parties collect "under the radar" could be shared with or used by other entities. Collecting ID is above the radar and may force people to think twice The "platforms" don't care about "privacy" except to control it. Their "business model" relies on defeating "privacy", reshaping the notion into one where privacy from the "platform" does not exist Internet "privacy" and mass data collection about people via "platforms" are not compatible goals "... our founders displayed a fondness for hyperbolic vilification of those who disagreed with them. In almost every meeting, they would unleash a one-word imprecation to sum up any and all who stood in the way of their master plans. "Bastards!" Larry would exclaim when a blogger raised concerns about user privacy." - Douglas Edwards, Google employee number 59, from 2011 book "I'm feeling lucky" If a user decides to stop using a third party "platform" intermediary (middleman) that engages in data collection, surveillance and ad services, for example, because they wish to avoid "age verification", then this could be the first step toward meaningful improvements in "internet privacy". People might stop creating "accounts", "signing in" and continuing to be complacent toward the surreptititious collection of data that is subsequently associated with their identity to create "profiles"
- muyuu 8mo agopeople really believe this coordinated push across jurisdictions is about kids and verifying their age? this excuse to try to end pseudonimity on the web is as old as the mainstream internet itself to a lot of people it never sat well that people could just go online and say whatever they want, and communicate with each other unsupervised at large scale, and be effectively untargetable while doing so - that model of the internet was only allowed because it happened under the radar and those uncomfortable with it have been fighting it since they got the memo
- Saline9515 8mo agoZero-knowledge proofs exist, that verify that a user's id holds certain properties, without leaking said ID.
- user3939382 8mo agoCorporate interests don’t care about data privacy or security they care about liability and compliance which are not the same thing. Major banks and government institutions can’t even be bothered to implement the NIST password guidelines. If they got their gdpr soc2 fedramp whatever it’s green lights and the rest is insurance.
- stainablesteel 8mo agothis is a broader parenting problem, the state doesn't need to do this politicians are interested in it because they're begging for some way to censor the internet, which would actually be even worse for parenting because now it prevents children from ever learning to be responsible with these highly addictive platforms
- jajuuka 8mo agoI feel like the ending undermines the whole piece. Throwing your hands up and going "we should do nothing" isn't really a solution. If a compromise exists I think it's adding age requests on device setup. There wouldn't be any verification but it could be used as a way to limit access to content globally. Content provides would just need a simple API to check if the age range fits and move right along. This puts more onus on parents and guardians to ensure their child's devices are set up correctly. The system wouldn't be perfect and people using something like Gentoo would be able to work around it, but I think it helps address the concerns. A framework would need to be created for content providers to enforce their own rating system but I don't think it's an impossible task. It obviously wouldn't cover someone not rating content operating out of Romania, but should be part of the accepted risk on an open internet. Personally I do agree with the "do nothing" stance, but I don't think it's going to hold up among the wider public. The die is cast and far too many average people are supporting moves like this. So the first defense should be to steer that conversation in a better way instead of stonewalling.
- Seattle3503 8mo ago> Personally I do agree with the "do nothing" stance, but I don't think it's going to hold up among the wider public. The die is cast and far too many average people are supporting moves like this. So the first defense should be to steer that conversation in a better way instead of stonewalling. I agree with this, and I find it frustrating how many people refuse to see this. It seems a lot of people would rather be "right" than compromise and keep the world closer to their stated values.
- kjeldsendk 8mo agoSurprisingly there is solutions that work just fine. It's like bankid or myid works in Scandinavian countries. When you need to identify yourself you are challenged by a 3rd party trusted service. Making this a age verification should be very easy. https://www.mitid.dk/en-gb/about-mitid/?language=en-gb https://www.mitid.dk/en-gb/about-mitid/?language=en-gb
- ltbarcly3 8mo agoIt's amazing how much it's possible to foment arguments against something if you are very well funded and a regulation will cost your industry a lot of money. Age verification is a good thing. Giving children unrestricted access to hardcore pornography is bad for them. Whatever arguments you want to make, fundamentally this is true.
- EmbarrassedHelp 8mo agoAge verification is fundamentally harmful and is an attack on user privacy. Age verification is being heavily lobbied for by tech companies that are hoping to get rich off of violating your privacy. Anonymous age verification is fundamentally impossible. It is especially a bad idea for adult content, as a person's perfectly legal sexual beliefs and fantasies can permanently destroy their lives if that information got out. Parental controls are the only ethical, secure, and privacy protecting way forward here.
- ltbarcly3 7mo agoYou are begging the question. If age verification is required, it's not 'perfectly legal' to access weird porn without going through age verification. There is no right, or even a debate about whether there should be a right, to consume digital streams of other people engaging in sexual acts in total anonymity without proving age. In fact being able to do this at all is something that didn't exist until about 25 years ago, before that you had to drive down to a video store and rent a DVD or tape. At that video store you would have to show an ID to get an account, and there would be a permanent record at the store of what you have rented. I get that people want to watch people engage in acts that they themselves find embarrassing and shameful. I don't agree that this is healthy, but if it's legal then I have no standing to complain much. However, it's not legal to provide videos of hardcore sex to children, which you are insisting is necessary to allow adults to consume videos of hardcore sex acts in perfect anonymity, which wasn't even a thing that was possible until very recently. Your argument is just stupid and absurd on its face.
- nottorp 8mo agoHow about we accept age verification but every parliamentary type that voted in favor goes to jail for just one year for each data breach? Practically that means all of them will be imprisoned for life, of course.
- fdefitte 8mo ago[dead]
- 111011111 8mo agoIsn't clear whether the paradox is biometric verification or ID data collection.
- chaostheory 8mo agoThat’s the point: enable mass surveillance and thee loss of privacy under the guise of another cause, usually “protecting the children”.
- alecco 8mo agoThe purpose is to control the Internet. They've been trying this for ages. They tried with terrorism and other things. Now the excuse is protecting children. Not exactly a good moment for this caste of politicians to pretend they care about children's well-being, though.
- hash07e 8mo agoSame people who are on Epstein files wants to protect children?
- Ylpertnodi 8mo agoNo. They want to fuck everybody.
- cowboylowrez 8mo ago[flagged]
- tsoukase 8mo agoSocial media, at least, are reaching the state the smoking had in the 80's when it started to be banned. After an era of praising (00's) scepticism followed (10's) until an underage ban comes (20's). Maybe in the 30's they will be banned in public spaces! The problem of identifying a value for each person is very difficult. But government's role stops there. Until the teenager's screen more factors stay in the middle (parents, peers, criminals). I am curious how it turns out eventually. As a parent, I have already banned SM for my children, so not "affected" by the new policy.
- Gigachad 8mo agoBan in public spaces might not make sense since there isn't a proximity hazard like smoke. But I can imagine after kids are banned from social media and we see how this was an obviously positive effect on their mental health, we will begin to acknowledge that this stuff is toxic for adults as well. We could start to ban many of the mechanisms social media companies have deployed over the last 10 years. Infinite scrolling, algorithmic feeds of "creator" content, AI generated ragebait from bot accounts, etc. I'd love to see social media reverted back to when it was just holiday photos from your friends.
- JB_5000 8mo agogood breakdown of the tradeoffs but it kinda stops at critique. explains why age verification becomes invasive but doesnt really propose what a workable alternative looks like. feels like we need concrete models or architectures not just pointing out the trap.
- wenngle 8mo agoIs this article AI-generated? https://www.pangram.com/history/f421130b-eefc-4f8c-b380-da0ac3612332/?ucc=MYx9WjFQLII https://www.pangram.com/history/f421130b-eefc-4f8c-b380-da0a... . I find it worrying that authors don't disclose the amount of AI assistance used in drafting and editing upfront. It sets a worrying precedent where everything is AI unless proven otherwise.
- tosti 8mo agoAge verification is age discrimination. Some can be 50 and still be clueless who to trust and what to do. Every kind of discrimination merely shifts the burden. And thinking of the children as an excuse for draconian law is itself child abuse. It's using children as a shield to take cover. EDIT: I'd like to add that if age verification becomes a thing, we should also have an online drug test, insurance verification, financial wellbeing tests, mental health checks and a badge of dishonor for anyone who fails to comply.
- PastScales 8mo agoI have been a kid and now a parent. It is impossible with the tools available to proof kids from the internet. If it's not a parent it's at a friends house, school devices, or a dedicated sense of curiosity. Two things tech companies want to protect: The perception of anonymity Who gets to collect that information I agree that a smaller loop of people should have that data but the loop is growing every day. So if it ruins the perception anonymity for young naieve users so be it. I'm not saying it's impossible to be somewhat anon, I'm just saying untrained users should understand the environment they're interacting with before they get hooked on useless products.
- guptadeepak 8mo agoAge verification is a tough problem. I ran into this when building a kids' education app a few years ago. We explored a bunch of options, from asking for the last four digits of their parents' SSN (which felt icky, even though it's just a partial number) to knowledge-based authentication (like security questions, but for parents). Ultimately, we went with a COPPA-compliant verification service, but it added friction to the signup process. It's a trade-off between security and user experience, and there's no perfect solution, unfortunately.
- stubish 8mo agoStarts off with a flawed assumption, playing into the hands of people who want surveillance. "The only way to prove that someone is old enough to use a site is to collect personal data about who they are. And the only way to prove that you checked is to keep the data indefinitely." If you start by legislating that you can't collect personal data or ID, then you are forced to do your age verification through other means. And legislate the government can't see what websites a user is visiting if you can to stop overreach. End result is a workable solution, zero knowledge proof or similar where government (the source of your ID documents) signs a token brokered by a proxy. But when you start arguments from the position of 'no way to do this without violating privacy', the end result will be to violate privacy, because it seems an awful lot of people are demanding age verification and will sacrifice if they believe it is necessary.
- andrepd 8mo ago> The only way to prove that someone is old enough to use a site is to collect personal data about who they are. And the only way to prove that you checked is to keep the data indefinitely. Well isn't this premise false from the get go? Many countries (not the US sure, but others) have digitised ID. Services can request info from the ID provider; in this case social media websites would simply request a bool isOver16, literally one bit of information, to grant access. No other information needs to be leaked, and no need for idiotic setups like sending photos of your passport to god knows what website (or god knows what external vendor that website uses for ID verification). Seems silly to worry about this when social media itself is predicated on collecting gigabytes of data about you daily. Again, this is not about half assed solutions that force you to send photos of your passport to websites. That's a terrible idea for the reasons discussed in the article. But it's obviously false that this is the only way.
- throwaway85825 8mo agoThe powers that be are 'correcting' the mistake of the anonymous internet where anyone can call a politician fat and the police can't arrest them for it.
- nanobuilds 8mo agoImagine if regular TV with age warnings in the beginning of programs made you fax your ID to the channel headquarters before you could watch PG13+ or whatever movie. This is obviously a privacy nightmare and a suboptimal solution. A good solution that respects privacy and helps reduce the exposure to harmful content at a young age is not very obvious though (but common sense and parental guidance seems to be the first step)
- rogerwong 8mo agoI really do think age verification should be at the device level, not per app or website. Parents can and should lock down their children's devices. I know device manufacturers don't want to take on that legal burden, but the tech is _right there!_
- gverrilla 8mo agoDefending the free internet nowadays means defending these sv criminals.
- cratermoon 8mo ago"The only way to prove that someone is old enough to use a site is to collect personal data about who they are." This is not true, as others have pointed out. Kind of sad to see no mention of privacy-preserving technology already in use in an IEEE article.
- sharmi 8mo ago[dead]
- ArchieScrivener 8mo ago'You must be 13 years old or older to create an account on this forum.' Yeah, sure. Whatever you say, Jack.
- JamesLeonis 8mo agoThe elephant in the room is 'unverified' users will overwhelmingly be underage kids, and that absence will be tracked across the internet. This whole thing inadvertently exposes who are the kids vs the adults programmatically. Second, if all it takes to get into underage spaces is not being verified, predators *will* notice and exploit this hole. Even the absence of information is information. > The Roblox games site, which recently launched a new age-estimate system, is already suffering from users selling child-aged accounts to adult predators seeking entry to age-restricted areas, Wired reports. I rest my case.
- godelski 8mo ago> Second, if all it takes to get into underage spaces is not being verified, predators *will* notice and exploit this hole. Well the default state is "assume underage". So the default state is be in same location as children. There's nothing for predators to exploit, they get access by default. Which once people realize that, it all becomes really silly. The only way it would really work is by verifying that people are children, so only children can be in the gated location. But then you need to do mass surveillance on children and I think even the average person realizes this just makes that a great place for predators and the damage caused by a leak is far greater to children. Not to mention the impractical nature of it as children are less likely to able to verify themselves and honestly, you expect kids to jump through extra hoops? Anyone that believes these systems will keep predators away from children haven't thought about even the most basic aspects of how these systems work. They cannot do what they promise
- with 8mo agokids will just use their parents' credentials. it's not an edge case, it will actually just be a default behavior, I promise. platforms need to be safe by default, but that's the problem - safe by default doesn't play nice with engagement. platforms need engagement for profit. chicken and egg.
- stevenjgarner 8mo agoLooking at actual data regarding Australia's landmark legislation setting a minimum age of 16 for social media access with enforcement starting on December 10, 2025 indicates weakened data protection. The Australian data suggests that while the legislation has successfully cleared the decks of millions of underage accounts (4.7 million account deactivations together with increased VPN usage and "ghost" accounts to bypass restrictions), it has simultaneously forced platforms to rely on third-party identity vendors, with the following failures so far: 1) Persona (Identity Vendor) Exposure (Feb 20, 2026): researchers discovered an exposed frontend belonging to Persona, an identity verification vendor used by platforms like Discord. This system was performing over 260 distinct checks, including facial recognition and "adverse media" screening, raising massive concerns about the scope creep of age verification. 2) Victorian Department of Education (Jan 2026): a breach impacting all 1,700 government schools exposed student names and encrypted passwords. This is a primary example of how child-related data remains a high-value target. 3) Prosura Data Breach (Jan 4, 2026): this financial services firm suffered a breach of 300,000 customer records. 4) University of Sydney (Dec 2025): a code library breach affected 27,000 people right as the new legislation was rolling out.
- consumer451 7mo agoIt is quite interesting that, according to a generally reliable YouTuber, Australian age verification was pushed by an ad agency whose major clients were upset about upcoming legislation regulating online gambling. It was a very successful distraction. > Australia's Social Media Ban is a Win for Gambling Companies https://www.patreon.com/posts/146315894 https://www.patreon.com/posts/146315894 (supporting links and transcript) https://www.crikey.com.au/2025/12/12/pro-teen-social-media-ban-group-funded-firm-making-gambling-ads/ https://www.crikey.com.au/2025/12/12/pro-teen-social-media-b... (the smoking gun) https://www.youtube.com/watch?v=mJi6N_6RmtU https://www.youtube.com/watch?v=mJi6N_6RmtU
- shevy-java 7mo agoThey want to kill anonymity on the open web. This is why I am against that.
- d--b 7mo agoI don’t understand this. Age verification is not more difficult than a payment system. I mean, if I can pay on a website without the website to know my credit card number, I should be able to prove my age without the website to know anything about me either. France has a ID verification system for all its service. You’d think they should be able to provide a hook that lets people prove they’re over the age limit to any third party without the third party knowing. It seems fairly basic. There is a solution to this. There are privacy issues on the internet, but I think this ain’t one.
- seany 7mo agoIsn't hosting stuff on tor/i2p the solution here? Putting stuff technically out of bounds of regulation had always seemed like the ideal end goal
- DoingIsLearning 7mo agoPalantir.
- aesopturtle 7mo agoAge checks sound simple, but they tend to turn into “please create a permanent ID for the internet.” I’d love a version that’s more like a one-time wristband than a loyalty card.
- p0w3n3d 7mo agomandatory loyalty card (won't sell you bread if you don't present it) with additional database of your extra-shop activities
- budududuroiu 7mo agoAge verification is one of the dumbest things humanity is wasting it's resources on. From every political angle, the messaging seems to be "we want you to give birth to many kids, but we don't trust you raising them"
- theodric 7mo agoI'm happy to see the IEEE talking about this, and to see the topic getting attention in the technical press. The problem is, I think (for the most part) that technical people already Get It. Who we need to convince are average, non-technical voters who don't know, don't understand, think it's a good thing, or would happily jump feet-first into a wood chipper if someone told them it would protect the children. I also suspect that social media has damaging effects on kids, and they probably shouldn't have access to it, but not like this. I'd probably be quicker to support something like saying that individuals <18 aren't allowed to buy or possess a phone or tablet that has access to an app store or web browser, and only offers voice- and text-based communications channels. Ok, so now it all happens on a laptop? What's "a tablet?" Is a Chromebook a tablet? It's fucking impossible.
- Grimeton 7mo agoThey could just issue a x509 cert with an above 18 attribute and nothing else. You're not 18 yet? No Problem we just give you two certs with different valid from/to ranges that overlap and don't give away your birthday. Problem solved.
- Borealid 7mo agoSteelmanning the opposing position: one adult shares their certificate with every child on the planet. Because it has no attributes (not even a unique serial number that could be used to track it) the whole scheme is now defeated.
- fragmede 7mo agoWhich, adult is merely someone who's just turned 18. What're the chances that any of them just post the thing up on 4chan? (I'm going to go with 100% chance of that happening.)
- egorfine 7mo agoNot really. If you take their rhetoric at face value ("Think of the children") then sure, it undermines everyone's data protection. I will go as far as to assume that no one on HN believes this is done for the children. It's been done to censor people and ID the majority of normies online. And when you think of this, the undermining of everyone's data protection is note an undesired side effect, it's the goal.
- eleveriven 7mo agoWe've spent 30 years telling people "don't share personal info online" and now the compliance path is "upload your ID or face so you can browse memes"
- mirpa 7mo agoNon of which is necessary to verify you crossed age threshold. Websites are just lazy, maybe on purpose. Accepting this kind of low effort age verification would be foolish.
- thenoblesunfish 7mo agoI was hoping for more on "... The only way to prove that you checked is to keep the data indefinitely." What do the laws say on this? What data is this? I would have assumed that just like a bouncer can check my ID and hand it back to me, a digital system can verify my identity and not hold onto everything (e.g. the actual photo of my ID).
- deleted 7mo ago[deleted]
- Kazik24 7mo agoShouldn't the verification be other way around? That is, you need to prove that you are a child. Then the site can present you more strictly filtered content. Parent can sign child's device on first boot, token stored in TPM so that it's hard to remove. It's basically the same type of enforcement on sites, as they need to verify and filter content for children, or just block them. Most of the internet users are adults, why not make internet for adults by default.
- maximus-decimus 7mo agoSo you want porn on every web site and have kids prove that they're kids by issuing their school card (because they won't have a real id yet) so the porn get hidden for them or so they get entirely banned from the system? Nobody's ever gonna show an id to get banned from a website.
- Kazik24 7mo agoDo you see porn on every website right now, since we don't have widespread verification yet? The internet was designed for adults from the start, only in recent years we got a significant portion of kids on it. The thing is that if you are a kid, your device would be bought and signed by your parent, you have no way of refusing to show ID cause device does it automatically. Of course there is a problem that children could use parent's phone but that's also a way to circumvent current age verification propositions. The idea is just to sign device once for a kid and let them use it without constant worry.
- huflungdung 7mo ago[dead]
- lunias 7mo agoWhen I was a kid, my parents installed Net Nanny on our home computer. I installed a keylogger. No more Net Nanny; lots more EverQuest. I don't like age verification in general, for anything. The age gates in our society are very subjective. Many times my Dad would buy alcohol at the grocery store w/ me (underage) in tow, but they never asked for my ID or refused to sell to him. Now, when I go buy alcohol as an adult with my wife (we are both in our mid-late 30s) they ask to see her ID as well as mine? If she leaves her ID at home then she has to wait in the car because they will refuse the sale if she comes into the store and cannot prove her age. Buying a case of beer with a group of 8 year olds? No problem. Bottle of wine for you and your wife? Let me get both IDs.
- MisterTea 7mo ago> When I was a kid, my parents installed Net Nanny on our home computer. Putting up artificial walls is inviting someone to look behind them. Back in 1999 I was attending a city university and their computer labs were a mix of older Pentium machines running Windows 98 secured by netnanny. They disabled floppy booting in the BIOS and password protected it. Thing is, the old Dell cases were real easy to pop open and pull the CMOS battery out. That killed the BIOS password so I was able to floppy boot the machine and rename netnanny.exe to nutnanny.exe and Win 98 ran unimpeded. When I was done I would rename the exe, reboot and go on about my day. Nice try, uni admins.
- testing22321 7mo agoThe US is strange about alcohol. I remember plenty of times in my early 20s buying alcohol and they wanted to see the ID of everyone waiting on my car. In Australia you buy alcohol at the drive through. One person is 18 and you’re good.
- kazinator 7mo agoThe game Leisure Suit Larry in the Land of the Lounge Lizards [1987] did a good job of age verification. No personal info. Air gapped operation, pre-non-institutional-Internet.